CVE-2024-7093

Source
https://cve.org/CVERecord?id=CVE-2024-7093
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-7093.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-7093
Published
2024-08-01T21:07:35.787Z
Modified
2026-07-15T01:49:07.898737191Z
Severity
  • 9.4 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
Server-Side Template Injection in Dispatch Message Templates
Details

Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither properly sanitized nor sandboxed. This vulnerability enables users to construct command line scripts in their custom message templates, which are then executed whenever these notifications are rendered and sent out.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/7xxx/CVE-2024-7093.json",
    "cwe_ids": [
        "CWE-94"
    ],
    "cna_assigner": "netflix"
}
References

Affected packages

Git / github.com/netflix/dispatch

Affected ranges

Type
GIT
Repo
https://github.com/netflix/dispatch
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "v20240731"
        }
    ]
}

Affected versions

Other
v202001207
v20200421
v20200503
v20200506
v20200922
v20201001
v20201013
v20201027
v20201106
v20201119
v20201207
v202030505
v20210112
v20210210
v20210212
v20210224
v20210319
v20210506
v20210603
v20210714
v20210804
v20210913
v20211015
v20211116
v20220119
v20220214
v20220310
v20220322
v20220428
v20220504
v20220607
v20220706
v20220801
v20220915
v20221110
v20221207
v20230131
v20230213
v20230215
v20230309
v20230409
v20230606
v20230817c
v20230919
v20240605
v20200922.*
v20200922.1
v20210804.*
v20210804.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-7093.json"