Debian Package Tracker
Register | Log in
Subscribe

node-nunjucks

templating engine with inheritance, asynchronous control, and more

Choose email to subscribe with

general
  • source: node-nunjucks (main)
  • version: 3.2.4+~cs4.2.7-1
  • maintainer: Debian Javascript Maintainers (archive) (DMD)
  • uploaders: Pirate Praveen [DMD]
  • arch: all
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • stable: 3.2.3+dfsg+~cs1.0.1-3
  • testing: 3.2.4+~cs4.2.7-1
  • unstable: 3.2.4+~cs4.2.7-1
versioned links
  • 3.2.3+dfsg+~cs1.0.1-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.2.4+~cs4.2.7-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • node-nunjucks
action needed
lintian reports 1 error and 1 warning high
Lintian reports 1 error and 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2025-04-10 Last update: 2025-04-10 00:31
1 low-priority security issue in bookworm low

There is 1 open security issue in bookworm.

1 issue left for the package maintainer to handle:
  • CVE-2023-2142: (needs triaging) In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character.

You can find information about how to handle this issue in the security team's documentation.

Created: 2024-11-26 Last update: 2025-04-09 07:00
news
[rss feed]
  • [2025-04-09] node-nunjucks 3.2.4+~cs4.2.7-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-06] Accepted node-nunjucks 3.2.4+~cs4.2.7-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2022-11-26] node-nunjucks 3.2.3+dfsg+~cs1.0.1-3 MIGRATED to testing (Debian testing watch)
  • [2022-11-21] Accepted node-nunjucks 3.2.3+dfsg+~cs1.0.1-3 (source) into unstable (Jelmer Vernooij) (signed by: Jelmer Vernooij)
  • [2022-05-20] node-nunjucks 3.2.3+dfsg+~cs1.0.1-2 MIGRATED to testing (Debian testing watch)
  • [2022-05-15] Accepted node-nunjucks 3.2.3+dfsg+~cs1.0.1-2 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2022-05-15] Accepted node-nunjucks 3.2.3+dfsg+~cs1.0.1-1 (source all) into unstable, unstable (Debian FTP Masters) (signed by: Praveen Arimbrathodiyil)
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 0
  • M&W: 1
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (1, 1)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.2.4+~cs4.2.7-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing