Threats Tagged 'cve-2024-22195'
View all threats tagged with 'cve-2024-22195'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2024-22195'
Click on any threat for detailed analysis and mitigation recommendations
0 A moderate severity vulnerability (CVE-2024-22195) exists in the python-jinja2 package used in Red Hat Enterprise Linux 8 and 9. The issue involves HTML attribute injection when user input is passed as keys to the xmlattr filter in Jinja2 templates. This vulnerability could allow unintended HTML attribute injection in affected applications. Red Hat has released security updates for python-jinja2 to address this issue. Applying the update and restarting all applications using Jinja2 is required to mitigate the vulnerability. Join the discussion | GCVE Database | 05/22/2024, 20:37:57 UTC Added: 06/02/2026, 21:44:03 UTC |
0 Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based. Join the discussion | CVE Database V5 | 01/11/2024, 02:25:44 UTC Added: 11/03/2025, 22:01:03 UTC |
Showing 1 to 2 of 2 results