Safety vulnerability ID: 73130
The information on this page was manually curated by our Cybersecurity Intelligence Team.
In ethyca-fides affected versions, the Email Templating feature implements Jinja2 without adequate input sanitization or rendering environment restrictions. This oversight creates a vulnerability to Server-Side Template Injection, potentially allowing Remote Code Execution by privileged users. In this context, a privileged user is defined as an Admin UI user with either the default 'Owner' or 'Contributor' role. Such users can exploit this vulnerability to escalate their access and execute arbitrary code on the underlying Fides Webserver container where the Jinja template rendering function operates.
Latest version: 2.51.1
Open-source ecosystem for data privacy as code.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application