[Apollo] Advisories Statistics light light Login

RLSA-2024:4231

Security Mirrored from RHSA-2024:4231
Issued at: 2024-07-15
Updated at: 2024-07-15

Synopsis

Moderate: python-jinja2 security update



Description

The python-jinja2 package contains Jinja2, a template engine written in pure Python. Jinja2 provides a Django inspired non-XML syntax but supports inline expressions and an optional sandboxed environment.

Security Fix(es):

* jinja2: accepts keys containing non-attribute characters (CVE-2024-34064)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 8 aarch64 Rocky Linux 8 x86_64

Fixes

2279476

CVEs

CVE-2024-34064

Affected packages

Rocky Linux 8 x86_64 - AppStream

python3-jinja2-0:2.10.1-5.el8_10.noarch.rpm python-jinja2-0:2.10.1-5.el8_10.src.rpm

Rocky Linux 8 aarch64 - AppStream

python3-jinja2-0:2.10.1-5.el8_10.noarch.rpm python-jinja2-0:2.10.1-5.el8_10.src.rpm