New Debian jinja2 3.1.2-1+deb12u1 fixes: This update addresses the following issues: * jinja2: HTML attribute injection when passing user input as keys to xmlattr filter (CVE-2024-22195) * jinja2: accepts keys containing non-attribute characters (CVE-2024-34064)
--- mirror/ftp/pool/main/j/jinja2/jinja2_3.1.2-1.dsc +++ apt/ucs_5.2-0-errata5.2-0/source/jinja2_3.1.2-1+deb12u1.dsc @@ -1,3 +1,9 @@ +3.1.2-1+deb12u1 [Sat, 07 Dec 2024 19:15:36 +0200] Adrian Bunk <bunk@debian.org>: + + * Non-maintainer upload. + * CVE-2024-22195: HTML attribute injection (Closes: #1060748) + * CVE-2024-34064: HTML attribute injection (Closes: #1070712) + 3.1.2-1 [Fri, 24 Feb 2023 16:15:45 +0100] Piotr Ożarowski <piotr@debian.org>: [ Thomas Goirand ] <http://piuparts.knut.univention.de/5.2-0/#3946687536095679621>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.2-0] 8611cd4aa2 Bug #57927: jinja2 3.1.2-1+deb12u1 doc/errata/staging/jinja2.yaml | 14 ++++++++++++++ 1 file changed, 14 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.2x8>