CVE-2023-2142
Estado: AnalizadaMedia (6.1)—
In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.36%
- Percentil entre todas las CVEs puntuadas: 28
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-2142",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-2142",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-11-27T16:17:55.829952Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@mozilla.org",
"affectedData": [
{
"vendor": "Mozilla",
"product": "Nunjucks",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "3.2.4",
"versionType": "semver"
}
],
"defaultStatus": "unknown"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:mozilla:nunjucks:*:*:*:*:*:*:*:*"
],
"vendor": "mozilla",
"product": "nunjucks",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "3.2.4",
"versionType": "semver"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-11-26T12:15:18.307",
"references": [
{
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1825980",
"tags": [
"Issue Tracking",
"Permissions Required"
],
"source": "security@mozilla.org"
},
{
"url": "https://github.com/mozilla/nunjucks/security/advisories/GHSA-x77j-w7wf-fjmw",
"tags": [
"Vendor Advisory"
],
"source": "security@mozilla.org"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@mozilla.org",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Nunjucks versions prior to version 3.2.4, it was \npossible to bypass the restrictions which are provided by the autoescape\n functionality. If there are two user-controlled parameters on the same \nline used in the views, it was possible to inject cross site scripting \npayloads using the backslash \\ character."
},
{
"lang": "es",
"value": "En las versiones de Nunjucks anteriores a la versión 3.2.4, era posible eludir las restricciones que proporciona la función de escape automático. Si hay dos parámetros controlados por el usuario en la misma línea utilizada en las vistas, era posible inyectar payloads de cross-site scripting utilizando el carácter de barra invertida \\."
}
],
"lastModified": "2026-06-17T05:51:35.577",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mozilla:nunjucks:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AEEE5C7E-56D7-4DB4-A58B-4AC206EDA1D3",
"versionEndExcluding": "3.2.4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@mozilla.org"
}