Server-Side Template Injection in Fides Privacy Engineering Platform
CVE-2024-45053

7.2HIGH

Key Information:

Vendor

Ethyca

Status
Vendor
CVE Published:
4 September 2024

What is CVE-2024-45053?

The Email Templating feature in the Fides privacy engineering platform, versions prior to 2.44.0, is susceptible to a Server-Side Template Injection vulnerability due to inadequate input sanitization and unrestricted rendering environments using Jinja2. Privileged users, such as those with default 'Owner' or 'Contributor' roles in the Admin UI, can exploit this vulnerability to escalate their access and execute arbitrary code on the underlying Fides Webserver container where template rendering occurs. It is essential for users to upgrade to Fides version 2.44.0 or later to mitigate exposure to this potential exploit.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.