drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen beliebiger Kommandos in python-jinja2
Name: |
Ausführen beliebiger Kommandos in python-jinja2 |
|
ID: |
RHSA-2019:1152-01 |
|
Distribution: |
Red Hat |
|
Plattformen: |
Red Hat Enterprise Linux |
|
Datum: |
Mo, 13. Mai 2019, 18:53 |
|
Referenzen: |
https://access.redhat.com/security/cve/CVE-2019-10906 |
|
Applikationen: |
Jinja2 |
|
Originalnachricht |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256
===================================================================== Red Hat Security Advisory
Synopsis: Important: python-jinja2 security update Advisory ID: RHSA-2019:1152-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:1152 Issue date: 2019-05-13 CVE Names: CVE-2019-10906 =====================================================================
1. Summary:
An update for python-jinja2 is now available for Red Hat Enterprise Linux 8.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux AppStream (v. 8) - noarch
3. Description:
The python-jinja2 package contains Jinja2, a template engine written in pure Python. Jinja2 provides a Django inspired non-XML syntax but supports inline expressions and an optional sandboxed environment.
Security Fix(es):
* python-jinja2: str.format_map allows sandbox escape (CVE-2019-10906)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
4. Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258
For the update to take effect, all applications using Jinja2 must be restarted.
5. Bugs fixed (https://bugzilla.redhat.com/):
1698839 - CVE-2019-10906 python-jinja2: str.format_map allows sandbox escape
6. Package List:
Red Hat Enterprise Linux AppStream (v. 8):
Source: python-jinja2-2.10.1-2.el8_0.src.rpm
noarch: python3-jinja2-2.10.1-2.el8_0.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2019-10906 https://access.redhat.com/security/updates/classification/#important
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/
Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1
iQIVAwUBXNlMXdzjgjWX9erEAQg/uBAAn12VyowxeAO9H8uOB4m+KivReOV2Wy8G sPznw985fIGJAfZfvHS3mkyEeXs1nIfRosrs5cJxCxMFXAVvMbX7IwMOXlUoK3dy C1hOkiScJBRhGoaeGeUQAui68KwCU4ZgakRYDfx9+2hBsJ8ZEfjmyD0j6pFJMWET I6CI1C3YyKrxqDgz5Ma8l9mE8B0ovLsaOeYXc0im/lo/+nQB23nqR8YZObPV5XLn 0nju0sJNz+kuOp3L+Pw4MLoJKqUccxc7xp30jU15yGmeSzdvxhkKGdpjJwy1Srpk oGiINPiYJibP5GqMaRSVEL0st4UYNcoqBUMWILCK0RQLpZTTzTtEtidUIKJ+Q4uW M2Fh5h7Ni3QTKzEZpbAadBn1e9kUPZ54Y3O6UmbFjzavTSJPy2GwUEtxKwTzKKwS rSwimvZuUY4NiXrYXa1TLxUdf6tjD/OEJYQmvUcFdII9r0QHd1yaWwQ5gBLiUYAc b4aoPLAii3f9pLa+b0tEl1YA52uIZutazy9QG4AklQ7HTxBn+2heT9KHD0yhifXT PyzXJhUoZA4lK1jeGoaiWqx1637tGokHPHFnOxqAPMjZTG+3SoATBh1TQGfCQYwj R9DQwyU/H4nDTy01AxzBbtKGAdqGYyQgC1oJ2jGl3rE5tXhIF5q3QTLvi0XYe8b6 0Qjnl7zqqks= =dKl4 -----END PGP SIGNATURE-----
-- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce
|
|
|
|