A moderate cross-site scripting vulnerability, CVE-2024-34064, affects Jinja2's xmlattr filter when applications pass unvalidated, user-controlled keys into the filter. Keys containing invalid HTML or XML attribute characters can inject additional attributes into rendered output, potentially allowing attacker-controlled script execution when another user views the affected page. Red Hat assigned the flaw a CVSS v3.1 score of 5.4 and noted that the preceding fix for CVE-2024-22195 blocked spaces but did not address other dangerous characters.
The issue is an instance of CWE-79, improper neutralization of input during web-page generation. Organizations should apply vendor fixes, prevent untrusted input from being used as xmlattr keys, validate inputs against strict allowlists, and use context-appropriate output encoding. Successful XSS exploitation can enable session-cookie theft, account takeover, unauthorized actions, and exposure of sensitive data; HttpOnly cookies and web application firewalls provide additional defense in depth.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:4522 to fix affected Automation Controller components in Ansible Automation Platform 2.4.
Red Hat issued RHSA-2024:4231 to fix python-jinja2 in Red Hat Enterprise Linux 8.
Red Hat fixed the Red Hat Developer Hub 1.2 on RHEL 9 image through advisory RHEA-2024:4071.
Red Hat issued RHSA-2024:3795 to remediate CVE-2024-34064 in fence-agents for RHEL 8.4 Advanced Update Support and related SAP, telecommunications, and extended-life-cycle offerings. Updated fence-agents 4.2.1-65.el8_4.15 packages were provided for x86_64 and ppc64le.
Red Hat issued RHSA-2024:3781 to fix python3x-jinja2 in Ansible Automation Platform 2.4 for RHEL 8 and python-jinja2 for RHEL 9.
Red Hat issued RHSA-2024:5810 and RHSA-2024:6011 to fix affected Ironic content in OpenShift Container Platform versions 4.12 and 4.13, respectively.
Red Hat fixed the affected fence-agents package on RHEL 8 through RHBA-2024:4238 for CVE-2024-34064, an XSS issue in Jinja2's xmlattr filter.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.