<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 05:05:05 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:2132 — Moderate: fence-agents security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:2132</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: fence-agents-aliyun, AlmaLinux:9: fence-agents-all, AlmaLinux:9: fence-agents-amt-ws, AlmaLinux:9: fence-agents-apc, AlmaLinux:9: fence-agents-apc-snmp, AlmaLinux:9: fence-agents-aws, AlmaLinux:9: fence-agents-azure-arm, AlmaLinux:9: fence-agents-bladecenter, AlmaLinux:9: fence-agents-brocade, AlmaLinux:9: fence-agents-cisco-mds and 45 more&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* urllib3: Request body not stripped after redirect from 303 status changes request method to GET (CVE-2023-45803)
* pycryptodome: side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex (CVE-2023-52323)
* jinja2: HTML attribute injection when passing user input as keys to xmlattr filter (CVE-2024-22195)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: fence-agents-aliyun, AlmaLinux:9: fence-agents-all, AlmaLinux:9: fence-agents-amt-ws, AlmaLinux:9: fence-agents-apc, AlmaLinux:9: fence-agents-apc-snmp, AlmaLinux:9: fence-agents-aws, AlmaLinux:9: fence-agents-azure-arm, AlmaLinux:9: fence-agents-bladecenter, AlmaLinux:9: fence-agents-brocade, AlmaLinux:9: fence-agents-cisco-mds and 45 more&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* urllib3: Request body not stripped after redirect from 303 status changes request method to GET (CVE-2023-45803)
* pycryptodome: side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex (CVE-2023-52323)
* jinja2: HTML attribute injection when passing user input as keys to xmlattr filter (CVE-2024-22195)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:2132</guid>
    </item>
    <item>
      <title>bdu:2024-00884</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-00884</link>
      <description>bdu:2024-00884</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-00884</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-22195</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-22195</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-jinja2, Alpaquita:stream: py3-jinja2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-jinja2, Alpaquita:stream: py3-jinja2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-22195</guid>
    </item>
    <item>
      <title>BREW-adr-viewer-CVE-2024-22195 — Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter</title>
      <link>https://cve.radiocsirt.org/vuln/brew-adr-viewer-cve-2024-22195</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: adr-viewer&lt;/p&gt;
&lt;p&gt;The `xmlattr` filter in affected versions of Jinja accepts keys containing spaces. XML/HTML attributes cannot contain spaces, as each would then be interpreted as a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. Note that accepting keys as user input is not common or a particularly intended use case of the `xmlattr` filter, and an application doing so should already be verifying what keys are provided regardless of this fix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: adr-viewer&lt;/p&gt;
&lt;p&gt;The `xmlattr` filter in affected versions of Jinja accepts keys containing spaces. XML/HTML attributes cannot contain spaces, as each would then be interpreted as a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. Note that accepting keys as user input is not common or a particularly intended use case of the `xmlattr` filter, and an application doing so should already be verifying what keys are provided regardless of this fix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-adr-viewer-cve-2024-22195</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0305 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0305</link>
      <description>certfr-2024-avi-0305</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0305</guid>
    </item>
    <item>
      <title>EUVD-2026-258564</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258564</link>
      <description>EUVD-2026-258564</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258564</guid>
    </item>
    <item>
      <title>fkie_cve-2024-22195</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-22195</link>
      <description>&lt;p&gt;Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-22195</guid>
    </item>
    <item>
      <title>GHSA-h5c8-rqwp-cp95 — Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h5c8-rqwp-cp95</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jinja2&lt;/p&gt;
&lt;p&gt;The `xmlattr` filter in affected versions of Jinja accepts keys containing spaces. XML/HTML attributes cannot contain spaces, as each would then be interpreted as a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. Note that accepting keys as user input is not common or a particularly intended use case of the `xmlattr` filter, and an application doing so should already be verifying what keys are provided regardless of this fix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jinja2&lt;/p&gt;
&lt;p&gt;The `xmlattr` filter in affected versions of Jinja accepts keys containing spaces. XML/HTML attributes cannot contain spaces, as each would then be interpreted as a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. Note that accepting keys as user input is not common or a particularly intended use case of the `xmlattr` filter, and an application doing so should already be verifying what keys are provided regardless of this fix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h5c8-rqwp-cp95</guid>
    </item>
    <item>
      <title>gsd-2024-22195</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-22195</link>
      <description>gsd-2024-22195</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-22195</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-22195 — Jinja vulnerable to Cross-Site Scripting (XSS)</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-22195</link>
      <description>msrc_CVE-2024-22195</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-22195</guid>
    </item>
    <item>
      <title>OESA-2024-1128 — python-jinja2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1128</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: python-jinja2, openEuler:20.03-LTS-SP4: python-jinja2, openEuler:22.03-LTS: python-jinja2, openEuler:22.03-LTS-SP1: python-jinja2, openEuler:22.03-LTS-SP2: python-jinja2, openEuler:22.03-LTS-SP3: python-jinja2&lt;/p&gt;
&lt;p&gt;Jinja2 is one of the most used template engines for Python. It is inspired by Django&amp;amp;apos;s templating system but extends it with an expressive language that gives template authors a more powerful set of tools. On top of that it adds sandboxed execution and optional automatic escaping for applications where security is important.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based.
(CVE-2024-22195)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: python-jinja2, openEuler:20.03-LTS-SP4: python-jinja2, openEuler:22.03-LTS: python-jinja2, openEuler:22.03-LTS-SP1: python-jinja2, openEuler:22.03-LTS-SP2: python-jinja2, openEuler:22.03-LTS-SP3: python-jinja2&lt;/p&gt;
&lt;p&gt;Jinja2 is one of the most used template engines for Python. It is inspired by Django&amp;amp;apos;s templating system but extends it with an expressive language that gives template authors a more powerful set of tools. On top of that it adds sandboxed execution and optional automatic escaping for applications where security is important.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based.
(CVE-2024-22195)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1128</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13581-1 — python310-Jinja2-3.1.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13581-1</link>
      <description>&lt;p&gt;python310-Jinja2-3.1.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python310-Jinja2-3.1.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13581-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-1473 — Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1473</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jinja2&lt;/p&gt;
&lt;p&gt;The `xmlattr` filter in affected versions of Jinja accepts keys containing spaces. XML/HTML attributes cannot contain spaces, as each would then be interpreted as a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. Note that accepting keys as user input is not common or a particularly intended use case of the `xmlattr` filter, and an application doing so should already be verifying what keys are provided regardless of this fix.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jinja2&lt;/p&gt;
&lt;p&gt;The `xmlattr` filter in affected versions of Jinja accepts keys containing spaces. XML/HTML attributes cannot contain spaces, as each would then be interpreted as a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. Note that accepting keys as user input is not common or a particularly intended use case of the `xmlattr` filter, and an application doing so should already be verifying what keys are provided regardless of this fix.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1473</guid>
    </item>
    <item>
      <title>RHBA-2024:0891 — Red Hat Bug Fix Advisory: fence-agents update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2024:0891</link>
      <description>&lt;p&gt;jinja2: HTML attribute injection when passing user input as keys to xmlattr filter&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;jinja2: HTML attribute injection when passing user input as keys to xmlattr filter&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2024:0891</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:1863-1 — Security update for python-Jinja2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:1863-1</link>
      <description>&lt;p&gt;Security update for python-Jinja2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-Jinja2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:1863-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-22195</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-22195</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jinja2, Ubuntu:Pro:16.04:LTS: jinja2, Ubuntu:Pro:18.04:LTS: jinja2, Ubuntu:20.04:LTS: jinja2, Ubuntu:22.04:LTS: jinja2, Ubuntu:24.04:LTS: jinja2&lt;/p&gt;
&lt;p&gt;Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jinja2, Ubuntu:Pro:16.04:LTS: jinja2, Ubuntu:Pro:18.04:LTS: jinja2, Ubuntu:20.04:LTS: jinja2, Ubuntu:22.04:LTS: jinja2, Ubuntu:24.04:LTS: jinja2&lt;/p&gt;
&lt;p&gt;Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-22195</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0522 — Red Hat Ansible Automation Platform: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0522</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, Dateien zu manipulieren, Phishing-Angriffe durchzuführen oder Cross-Site Scripting (XSS)-Angriffe auszuführen. Einige dieser Schwachstellen erfordern eine Benutzerinteraktion, um sie erfolgreich auszunutzen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen, Dateien zu manipulieren, Phishing-Angriffe durchzuführen oder Cross-Site Scripting (XSS)-Angriffe auszuführen. Einige dieser Schwachstellen erfordern eine Benutzerinteraktion, um sie erfolgreich auszunutzen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0522</guid>
    </item>
  </channel>
</rss>
