FlawAtlas
Search the atlas
SUSE-SU-2019:1554-1 Not scored

Security update for python-Jinja2

This update for python-Jinja2 fixes the following issues: Security issues fixed: - CVE-2016-10745: Fixed a sandbox escape caused by an information disclosure via str.format (bsc#1132174). - CVE-2019-10906: Fixed a sandbox escape due to information disclosure via str.format (bsc#1132323). - CVE-2019-8341: Fixed command injection in function from_string (bsc#1125815).

Exploit probability Not scored
Published June 18, 2019
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 4 python-Jinja2
SUSE:Enterprise Storage 5 python-Jinja2
SUSE:Linux Enterprise Point of Sale 12 SP2 python-Jinja2
SUSE:Manager Proxy 3.1 python-Jinja2
SUSE:Manager Proxy 3.2 python-Jinja2
SUSE:Manager Server 3.1 python-Jinja2
SUSE:Manager Server 3.2 python-Jinja2
SUSE:OpenStack Cloud 7 python-Jinja2

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2019:1554-1

This update for python-Jinja2 fixes the following issues: Security issues fixed: - CVE-2016-10745: Fixed a sandbox escape caused by an information disclosure via str.format (bsc#1132174). - CVE-2019-10906: Fixed a sandbox escape due to information disclosure via str.format (bsc#1132323). - CVE-2019-8341: Fixed command injection in function from_string (bsc#1125815).

View original source

05 / REFERENCES

Further evidence