In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character.
History

Wed, 27 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla nunjucks
CPEs cpe:2.3:a:mozilla:nunjucks:*:*:*:*:*:*:*:*
Vendors & Products Mozilla
Mozilla nunjucks
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Wed, 27 Nov 2024 01:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Tue, 26 Nov 2024 11:45:00 +0000

Type Values Removed Values Added
Description In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character.
Title Nunjucks autoescape bypass leads to cross site scripting
Weaknesses CWE-79
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2024-11-26T11:24:15.422Z

Updated: 2024-11-27T16:19:44.548Z

Reserved: 2023-04-18T08:19:20.097Z

Link: CVE-2023-2142

cve-icon Vulnrichment

Updated: 2024-11-27T16:19:37.787Z

cve-icon NVD

Status : Received

Published: 2024-11-26T12:15:18.307

Modified: 2024-11-27T17:15:05.200

Link: CVE-2023-2142

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-11-26T11:24:15Z

Links: CVE-2023-2142 - Bugzilla