possible to bypass the restrictions which are provided by the autoescape
functionality. If there are two user-controlled parameters on the same
line used in the views, it was possible to inject cross site scripting
payloads using the backslash \ character.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x77j-w7wf-fjmw | Nunjucks autoescape bypass leads to cross site scripting |
Wed, 27 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla nunjucks |
|
| CPEs | cpe:2.3:a:mozilla:nunjucks:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mozilla
Mozilla nunjucks |
|
| Metrics |
cvssV3_1
|
ssvc
|
Wed, 27 Nov 2024 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 26 Nov 2024 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character. | |
| Title | Nunjucks autoescape bypass leads to cross site scripting | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-11-27T16:19:44.548Z
Reserved: 2023-04-18T08:19:20.097Z
Link: CVE-2023-2142
Updated: 2024-11-27T16:19:37.787Z
Status : Analyzed
Published: 2024-11-26T12:15:18.307
Modified: 2025-06-24T16:42:52.533
Link: CVE-2023-2142
OpenCVE Enrichment
No data.
Github GHSA