Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Generate Jinja2 templates in sandboxed environment #639

Merged
merged 3 commits into from
Jun 28, 2024

Conversation

michaelnchin
Copy link
Member

Issue #, if available: CVE-2019-8341

Description of changes:

  • Switching Jinja2 Template() usages to SandboxedEnvironment.from_string() to mitigate a vulnerability.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@michaelnchin michaelnchin marked this pull request as ready for review June 28, 2024 01:53
@michaelnchin michaelnchin merged commit ee42964 into main Jun 28, 2024
3 checks passed
@michaelnchin michaelnchin deleted the jinja2-template-switch branch June 28, 2024 01:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: Resolved
Development

Successfully merging this pull request may close these issues.

1 participant