Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
DEBIAN-CVE-2016-10745
See a problem?
Please try reporting it
to the source
first.
Source
https://security-tracker.debian.org/tracker/CVE-2016-10745
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2016-10745.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2016-10745
Upstream
CVE-2016-10745
Published
2019-04-08T13:29:00Z
Modified
2025-09-30T03:54:32Z
Severity
8.6 (High)
CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVSS Calculator
Summary
[none]
Details
In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
References
https://security-tracker.debian.org/tracker/CVE-2016-10745
Affected packages
Debian:11
/
jinja2
Package
Name
jinja2
Purl
pkg:deb/debian/jinja2?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.9.4-1
Ecosystem specific
{ "urgency": "not yet assigned" }
Debian:12
/
jinja2
Package
Name
jinja2
Purl
pkg:deb/debian/jinja2?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.9.4-1
Ecosystem specific
{ "urgency": "not yet assigned" }
Debian:13
/
jinja2
Package
Name
jinja2
Purl
pkg:deb/debian/jinja2?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.9.4-1
Ecosystem specific
{ "urgency": "not yet assigned" }
Debian:14
/
jinja2
Package
Name
jinja2
Purl
pkg:deb/debian/jinja2?arch=source
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.9.4-1
Ecosystem specific
{ "urgency": "not yet assigned" }
DEBIAN-CVE-2016-10745 - OSV