In Nunjucks versions prior to version 3.2.4, it was
possible to bypass the restrictions which are provided by the autoescape
functionality. If there are two user-controlled parameters on the same
line used in the views, it was possible to inject cross site scripting
payloads using the backslash \ character.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 27 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla nunjucks
CPEs cpe:2.3:a:mozilla:nunjucks:*:*:*:*:*:*:*:*
Vendors & Products Mozilla
Mozilla nunjucks
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Wed, 27 Nov 2024 01:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Tue, 26 Nov 2024 11:45:00 +0000

Type Values Removed Values Added
Description In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character.
Title Nunjucks autoescape bypass leads to cross site scripting
Weaknesses CWE-79
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2024-11-27T16:19:44.548Z

Reserved: 2023-04-18T08:19:20.097Z

Link: CVE-2023-2142

cve-icon Vulnrichment

Updated: 2024-11-27T16:19:37.787Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-26T12:15:18.307

Modified: 2025-06-24T16:42:52.533

Link: CVE-2023-2142

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-11-26T11:24:15Z

Links: CVE-2023-2142 - Bugzilla

cve-icon OpenCVE Enrichment

No data.