Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2024-34064 Details

Description

Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. The fix for CVE-2024-22195 only addressed spaces but not other characters. Accepting keys as user input is now explicitly considered an unintended use case of the `xmlattr` filter, and code that does so without otherwise validating the input should be flagged as insecure, regardless of Jinja version. Accepting _values_ as user input continues to be safe. This vulnerability is fixed in 3.1.4.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://github.com/pallets/jinja/commit/0668239dc6b44ef38e7a6c9f91f312fd4ca581cb CVEPatch
https://github.com/pallets/jinja/security/advisories/GHSA-h75v-3vvj-5mfj CVEVendor Advisory
https://lists.debian.org/debian-lts-announce/2024/12/msg00009.html CVE
https://lists.fedoraproject.org/archives/list/[email protected]/message/567XIGSZMABG6TSMYWD7MIYNJSUQQRUC/ CVEMailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/GCLF44KY43BSVMTE6S53B4V5WP3FRRSE/ CVEMailing List

see all 13 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')[email protected]

Affected Products

ProductVersions
palletsprojects jinja
< 3.1.4

CPE

  • cpe:2.3:a:palletsprojects:jinja:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
fedoraproject fedora
39
40

CPE

  • cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

11 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2024-34064
NVD Published Date:
May 6, 2024
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2024-34064 Details - Not Deferred