WDscholia / scholia

Wikidata-based scholarly profiles
https://scholia.toolforge.org
Other
215 stars 77 forks source link

Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter #2439

Open fnielsen opened 3 months ago

fnielsen commented 3 months ago

Describe the bug https://nvd.nist.gov/vuln/detail/CVE-2024-22195

Additional context

Affected is < 3.1.3. Patched is 3.1.3

fnielsen commented 3 months ago

Jinja2>=3.1.3 in https://github.com/WDscholia/scholia/blob/master/requirements.txt

fnielsen commented 3 months ago

There is another requirement: https://github.com/WDscholia/scholia/blob/master/docs/requirements.txt