Skip to content

Commit

Permalink
Merge pull request #584 from rohanpm/jinja-safety
Browse files Browse the repository at this point in the history
safety: ignore irrelevant Jinja CVE
  • Loading branch information
rohanpm authored Jul 22, 2024
2 parents 8ee811f + 7ac9328 commit e3f0aba
Showing 1 changed file with 15 additions and 0 deletions.
15 changes: 15 additions & 0 deletions .safety-policy.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
security:
ignore-cvss-severity-below: 4
ignore-vulnerabilities:
70612:
# CVE-2019-8341, jinja2:
#
# In summary, the CVE says that it is unsafe to use untrusted
# user input as Jinja template sources as arbitrary code execution
# is possible. This should be obvious, so unsurprisingly Jinja
# maintainers and various third-parties reject/dispute the CVE,
# including Red Hat in https://bugzilla.redhat.com/show_bug.cgi?id=1677653
#
reason: >-
Not exploitable: user input is not used in any Jinja template sources
continue-on-vulnerability-error: False

0 comments on commit e3f0aba

Please sign in to comment.