Server-Side Template Injection in Fides Privacy Engineering Platform
CVE-2024-45053
What is CVE-2024-45053?
The Email Templating feature in the Fides privacy engineering platform, versions prior to 2.44.0, is susceptible to a Server-Side Template Injection vulnerability due to inadequate input sanitization and unrestricted rendering environments using Jinja2. Privileged users, such as those with default 'Owner' or 'Contributor' roles in the Admin UI, can exploit this vulnerability to escalate their access and execute arbitrary code on the underlying Fides Webserver container where template rendering occurs. It is essential for users to upgrade to Fides version 2.44.0 or later to mitigate exposure to this potential exploit.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
