Debian Package Tracker
Register | Log in
Subscribe

jinja2

Choose email to subscribe with

general
  • source: jinja2 (main)
  • version: 3.1.6-1
  • maintainer: Piotr Ożarowski (DMD)
  • uploaders: Debian Python Team [DMD]
  • arch: all
  • std-ver: 4.5.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.10-2
  • o-o-sec: 2.10-2+deb10u1
  • oldstable: 2.11.3-1
  • old-sec: 2.11.3-1+deb11u4
  • old-bpo: 3.0.3-1~bpo11+1
  • stable: 3.1.2-1+deb12u2
  • testing: 3.1.6-1
  • unstable: 3.1.6-1
versioned links
  • 2.10-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.10-2+deb10u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.11.3-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.11.3-1+deb11u4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.0.3-1~bpo11+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.1.2-1+deb12u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.1.6-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python-jinja2-doc
  • python3-jinja2
action needed
lintian reports 1 warning normal
Lintian reports 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2025-04-10 Last update: 2025-04-10 00:31
1 low-priority security issue in bookworm low

There is 1 open security issue in bookworm.

1 issue left for the package maintainer to handle:
  • CVE-2025-27516: (needs triaging) Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacker that controls the content of a template to execute arbitrary Python code. To exploit the vulnerability, an attacker needs to control the content of a template. Whether that is the case depends on the type of application using Jinja. This vulnerability impacts users of applications which execute untrusted templates. Jinja's sandbox does catch calls to str.format and ensures they don't escape the sandbox. However, it's possible to use the |attr filter to get a reference to a string's plain format method, bypassing the sandbox. After the fix, the |attr filter no longer bypasses the environment's attribute lookup. This vulnerability is fixed in 3.1.6.

You can find information about how to handle this issue in the security team's documentation.

Created: 2025-03-06 Last update: 2025-05-01 01:00
debian/patches: 2 patches to forward upstream low

Among the 2 debian patches available in version 3.1.6-1 of the package, we noticed the following issues:

  • 2 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2025-03-26 10:01
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 4.5.0).
Created: 2020-11-17 Last update: 2025-03-26 04:01
news
[rss feed]
  • [2025-04-30] Accepted jinja2 2.11.3-1+deb11u4 (source) into oldstable-security (Lucas Kanashiro)
  • [2025-04-13] Accepted jinja2 2.11.3-1+deb11u3 (source) into oldstable-security (Lucas Kanashiro)
  • [2025-03-31] jinja2 3.1.6-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-25] Accepted jinja2 3.1.6-1 (source) into unstable (Colin Watson)
  • [2025-03-01] Accepted jinja2 3.1.2-1+deb12u2 (source) into proposed-updates (Debian FTP Masters) (signed by: Lee Garrett)
  • [2025-02-08] jinja2 3.1.5-2 MIGRATED to testing (Debian testing watch)
  • [2025-02-03] Accepted jinja2 3.1.5-2 (source) into unstable (Alexandre Detiste)
  • [2025-01-29] jinja2 3.1.5-1 MIGRATED to testing (Debian testing watch)
  • [2025-01-22] Accepted jinja2 3.1.5-1 (source) into unstable (Sean Whitton)
  • [2025-01-21] jinja2 3.1.3-2 MIGRATED to testing (Debian testing watch)
  • [2025-01-08] Accepted jinja2 3.1.3-2 (source) into unstable (Alexandre Detiste)
  • [2024-12-20] jinja2 3.1.3-1.1 MIGRATED to testing (Debian testing watch)
  • [2024-12-18] Accepted jinja2 3.1.2-1+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Adrian Bunk)
  • [2024-12-15] Accepted jinja2 3.1.3-1.1 (source) into unstable (Adrian Bunk)
  • [2024-12-09] Accepted jinja2 2.11.3-1+deb11u2 (source) into oldstable-security (Adrian Bunk)
  • [2024-12-08] Accepted jinja2 2.11.3-1+deb11u1 (source) into oldstable-security (Adrian Bunk)
  • [2024-03-16] jinja2 3.1.3-1 MIGRATED to testing (Debian testing watch)
  • [2024-03-05] Accepted jinja2 3.1.3-1 (source) into unstable (Hans-Christoph Steiner)
  • [2024-01-23] Accepted jinja2 2.10-2+deb10u1 (source) into oldoldstable (Chris Lamb)
  • [2023-03-10] jinja2 3.1.2-1 MIGRATED to testing (Debian testing watch)
  • [2023-02-24] Accepted jinja2 3.1.2-1 (source) into unstable (Piotr Ożarowski)
  • [2022-09-18] jinja2 3.0.3-2 MIGRATED to testing (Debian testing watch)
  • [2022-09-13] Accepted jinja2 3.0.3-2 (source) into unstable (Thomas Goirand)
  • [2022-03-31] Accepted jinja2 3.0.3-1~bpo11+1 (all source) into bullseye-backports, bullseye-backports (Debian FTP Masters) (signed by: Andrew Shadura)
  • [2022-02-16] jinja2 3.0.3-1 MIGRATED to testing (Debian testing watch)
  • [2022-02-11] Accepted jinja2 3.0.3-1 (source) into unstable (Piotr Ożarowski)
  • [2021-10-13] jinja2 3.0.1-2 MIGRATED to testing (Debian testing watch)
  • [2021-10-01] Accepted jinja2 3.0.1-2 (source) into unstable (Thomas Goirand)
  • [2021-09-20] Accepted jinja2 3.0.1-1 (source) into experimental (Thomas Goirand)
  • [2021-03-11] jinja2 2.11.3-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 4 5
  • RC: 1 2
  • I&N: 2
  • M&W: 1
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 1)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.1.5-2ubuntu1
  • patches for 3.1.5-2ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing