Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE: 0000-0000 found in Jinja2 - Version: 2.11.3 [PYTHON] #95

Closed
github-actions bot opened this issue Aug 8, 2022 · 1 comment
Closed

CVE: 0000-0000 found in Jinja2 - Version: 2.11.3 [PYTHON] #95

github-actions bot opened this issue Aug 8, 2022 · 1 comment
Labels
Severity: Medium Medium severity Veracode Dependency Scanning A Veracode identified vulnerability

Comments

@github-actions
Copy link

github-actions bot commented Aug 8, 2022

Veracode Software Composition Analysis

Attribute Details
Library Jinja2
Description A very fast and expressive template engine.
Language PYTHON
Vulnerability Cross-Site Scripting (XSS)
Vulnerability description jinja2 is vulnerable to Cross Site Scripting. An attacker is able to inject and execute arbitrary Javascript through the gettext and ngettext function due to the lack of output sanitization.
CVE null
CVSS score 5.8
Vulnerability present in version/s 2.5-3.0.0
Found library version/s 2.11.3
Vulnerability fixed in version
Library latest version 3.1.2
Fix There is no fix version. Apply the following fix:

Links:

@github-actions github-actions bot added Severity: Medium Medium severity Veracode Dependency Scanning A Veracode identified vulnerability labels Aug 8, 2022
@mdesmet
Copy link
Member

mdesmet commented Aug 22, 2022

Jinja will be upgraded to 3.0 version in dbt1.3

See dbt-labs/dbt-core#4748

@mdesmet mdesmet closed this as completed Oct 22, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Severity: Medium Medium severity Veracode Dependency Scanning A Veracode identified vulnerability
Projects
None yet
Development

No branches or pull requests

1 participant