Files
community.general/docs/docsite/rst
James Cammarata ed56f51f18 Fixing security issue with lookup returns not tainting the jinja2 environment
CVE-2017-7481

Lookup returns wrap the result in unsafe, however when used through the
standard templar engine, this does not result in the jinja2 environment being
marked as unsafe as a whole. This means the lookup result looses the unsafe
protection and may become simple unicode strings, which can result in bad
things being re-templated.

This also adds a global lookup param and cfg options for lookups to allow
unsafe returns, so users can force the previous (insecure) behavior.
2017-05-08 12:43:46 -05:00
..
2017-01-06 09:16:59 -05:00
2017-01-06 09:16:59 -05:00
2017-03-01 20:23:18 -05:00
2017-01-06 09:16:59 -05:00
2017-01-06 09:16:59 -05:00
2017-01-06 09:16:59 -05:00
2017-01-06 09:16:59 -05:00
2017-01-06 09:16:59 -05:00
2017-01-06 09:16:59 -05:00
2017-04-20 14:57:34 +01:00
2017-01-06 09:16:59 -05:00
2017-01-06 09:16:59 -05:00
2017-01-06 09:16:59 -05:00
2017-01-10 12:58:22 -08:00
2017-03-15 15:32:30 -04:00
2017-01-06 09:16:59 -05:00
2017-01-06 09:16:59 -05:00
2017-01-06 09:16:59 -05:00
2017-02-14 10:47:37 -05:00
2017-01-06 09:16:59 -05:00
2017-01-06 09:16:59 -05:00
2017-01-17 18:55:03 -08:00
2017-03-31 00:53:53 -04:00
2017-04-12 13:49:26 -04:00
2017-01-06 09:16:59 -05:00
2017-01-06 09:16:59 -05:00