The vendor explicitly identifies these products as affected by this CVE.
- openshift-lightspeed-tech-preview/lightspeed-service-api-rhel9.src as a component of OpenShift Lightspeed
- ansible-tower.src as a component of Red Hat Ansible Automation Platform 1.2
- python-jinja2 as a component of Red Hat Enterprise Linux 6
- python-jinja2.src as a component of Red Hat Enterprise Linux 6
- rhelai1/bootc-amd-rhel9.src as a component of Red Hat Enterprise Linux AI (RHEL AI)
- rhelai1/bootc-aws-nvidia-rhel9.src as a component of Red Hat Enterprise Linux AI (RHEL AI)
- rhelai1/bootc-azure-amd-rhel9.src as a component of Red Hat Enterprise Linux AI (RHEL AI)
- rhelai1/bootc-azure-nvidia-rhel9.src as a component of Red Hat Enterprise Linux AI (RHEL AI)
- rhelai1/bootc-gcp-nvidia-rhel9.src as a component of Red Hat Enterprise Linux AI (RHEL AI)
- rhelai1/bootc-ibm-nvidia-rhel9.src as a component of Red Hat Enterprise Linux AI (RHEL AI)
- rhelai1/bootc-intel-rhel9.src as a component of Red Hat Enterprise Linux AI (RHEL AI)
- rhelai1/bootc-nvidia-rhel9.src as a component of Red Hat Enterprise Linux AI (RHEL AI)
- Summary
- A flaw was found in the Jinja2 package. A bug in the Jinja compiler allows an attacker that controls both the content and filename of a template to execute arbitrary Python code, regardless of Jinja's sandbox being used. An attacker needs to be able to control both the filename and the contents of a template. Whether that is the case depends on the type of application using Jinja. This vulnerability impacts users of applications that execute untrusted templates where the template author can also choose the template filename.
- Remediation
- Red Hat Ansible Automation Platform
