In Nunjucks versions prior to version 3.2.4, it was
possible to bypass the restrictions which are provided by the autoescape
functionality. If there are two user-controlled parameters on the same
line used in the views, it was possible to inject cross site scripting
payloads using the backslash \ character.
Metrics
Affected Vendors & Products
References
History
Wed, 27 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mozilla
Mozilla nunjucks |
|
CPEs | cpe:2.3:a:mozilla:nunjucks:*:*:*:*:*:*:*:* | |
Vendors & Products |
Mozilla
Mozilla nunjucks |
|
Metrics |
cvssV3_1
|
ssvc
|
Wed, 27 Nov 2024 01:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Tue, 26 Nov 2024 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character. | |
Title | Nunjucks autoescape bypass leads to cross site scripting | |
Weaknesses | CWE-79 | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mozilla
Published: 2024-11-26T11:24:15.422Z
Updated: 2024-11-27T16:19:44.548Z
Reserved: 2023-04-18T08:19:20.097Z
Link: CVE-2023-2142
Vulnrichment
Updated: 2024-11-27T16:19:37.787Z
NVD
Status : Received
Published: 2024-11-26T12:15:18.307
Modified: 2024-11-27T17:15:05.200
Link: CVE-2023-2142
Redhat