Description
In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commands. Jinja does not enable sandboxed mode by default due to backwards compatibility. Stackstorm now sets sandboxed mode for jinja by default.
Published: 2021-12-15
Score: 8.8 High
EPSS: 2.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-31477 In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commands. Jinja does not enable sandboxed mode by default due to backwards compatibility. Stackstorm now sets sandboxed mode for jinja by default.
History

No history.

Subscriptions

Stackstorm Stackstorm
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T04:25:16.850Z

Reserved: 2021-12-06T00:00:00.000Z

Link: CVE-2021-44657

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-15T15:15:11.597

Modified: 2024-11-21T06:31:19.880

Link: CVE-2021-44657

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses