Your submission was sent successfully! Close

CVE-2016-10745

Published: 8 April 2019

In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.

Priority

Medium

CVSS 3 base score: 8.6

Status

Package Release Status
jinja2
Launchpad, Ubuntu, Debian
bionic Not vulnerable
(2.10-1)
cosmic Not vulnerable
(2.10-1)
disco Not vulnerable
(2.10-1)
precise
Released (2.6-1ubuntu0.2)
trusty
Released (2.7.2-2ubuntu0.1~esm1)
upstream
Released (2.9.4-1)
xenial
Released (2.8-1ubuntu0.1)