-
Story
-
Resolution: Done
-
Critical
-
None
-
None
-
Future Sustainability
-
False
-
-
False
-
None
-
3
-
None
-
None
-
OAPE Sprint 268
-
1
Currently, upstream https://github.com/operator-framework/ansible-operator-plugins project is using jinja2 v3.1.5, which is now vulnerable as per CVE-2025-27516.
Create an issue upstream and propose a PR to fix the CVE upstream.
This vulnerability is fixed in v3.1.6
References
GHSA-cpwx-vrp4-4pq7
• https://www.cve.org/CVERecord?id=CVE-2025-27516
• https://nvd.nist.gov/vuln/detail/CVE-2025-27516
• GHSA-cpwx-vrp4-4pq7
• pallets/jinja@90457bb
- blocks
-
OAPE-35 Rebase openshift/ansible-operator-plugins to upstream operator-framework/ansible-operator-plugins v1.37.2
-
- Closed
-