Path to this page:
Subject: CVS commit: pkgsrc/textproc/py-jinja2
From: Adam Ciarcinski
Date: 2024-05-06 06:39:49
Message id: 20240506043949.823CFFA2C@cvs.NetBSD.org
Log Message:
py-jinja2: updated to 3.1.4
Version 3.1.4
The xmlattr filter does not allow keys with / solidus, > greater-than sign, \
or = equals sign, in addition to disallowing spaces. Regardless of any \
validation done by Jinja, user input should never be used as keys to this \
filter, or must be separately validated first. GHSA-h75v-3vvj-5mfj
Files: