CVE-2015-5215
Last modified
CVE-2015-5215 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The default configuration of the Jinja templating engine used in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not enable auto-escaping, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via template variables. NOTE: This may be a duplicate of CVE-2015-5216. EPSS estimates a 1.07% chance of exploitation in the next 30 days.
Description
The default configuration of the Jinja templating engine used in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not enable auto-escaping, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via template variables. NOTE: This may be a duplicate of CVE-2015-5216. Moreover, the Jinja development team does not enable auto-escape by default for performance issues as explained in https://jinja.palletsprojects.com/en/master/faq/#why-is-autoescaping-not-the-default.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ipsilon-Project | Ipsilon | >= 0.1.0, < 1.0.1 |
References
- http://www.openwall.com/lists/oss-security/2015/10/23/10Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1255168Issue Tracking, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/10/23/10Mailing List, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1255168Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-5215?
How severe is CVE-2015-5215?
How do I fix CVE-2015-5215?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-5209Apache Struts 2.x before 2.3.24.1 allows remote attackers to…
- CVE-2015-5210Open redirect vulnerability in Apache Ambari before 2.1.2 al…
- CVE-2015-5211Under some situations, the Spring Framework 4.2.0 to 4.2.1, …9.6
- CVE-2015-5212Integer underflow in LibreOffice before 4.4.5 and Apache Ope…
- CVE-2015-5213Integer overflow in LibreOffice before 4.4.5 and Apache Open…
- CVE-2015-5214LibreOffice before 4.4.6 and 5.x before 5.0.1 and Apache Ope…
- CVE-2015-5216The Identity Provider (IdP) server in Ipsilon 0.1.0 before 1…6.1
- CVE-2015-5217providers/saml2/admin.py in the Identity Provider (IdP) serv…
- CVE-2015-5218Buffer overflow in text-utils/colcrt.c in colcrt in util-lin…
- CVE-2015-5219The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does …7.5
- CVE-2015-5220The Web Console in Red Hat Enterprise Application Platform (…
- CVE-2015-5221Use-after-free vulnerability in the mif_process_cmpt functio…
Are you affected by CVE-2015-5215?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
