Description
Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither properly sanitized nor sandboxed. This vulnerability enables users to construct command line scripts in their custom message templates, which are then executed whenever these notifications are rendered and sent out.
Published: 2024-08-01
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-48079 Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither properly sanitized nor sandboxed. This vulnerability enables users to construct command line scripts in their custom message templates, which are then executed whenever these notifications are rendered and sent out.
History

No history.

Subscriptions

Netflix Dispatch
cve-icon MITRE

Status: PUBLISHED

Assigner: netflix

Published:

Updated: 2024-08-02T16:04:37.541Z

Reserved: 2024-07-24T21:43:55.252Z

Link: CVE-2024-7093

cve-icon Vulnrichment

Updated: 2024-08-02T16:04:26.678Z

cve-icon NVD

Status : Deferred

Published: 2024-08-01T21:16:05.100

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-7093

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses