CVE Vulnerabilities

CVE-2014-0012

Published: May 19, 2014 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
4.4 MODERATE
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a users uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.

Affected Software

Name Vendor Start Version End Version
Jinja2 Pocoo 2.7.2 (including) 2.7.2 (including)
Jinja2 Ubuntu lucid *
Jinja2 Ubuntu precise *
Jinja2 Ubuntu quantal *
Jinja2 Ubuntu raring *
Jinja2 Ubuntu saucy *
Jinja2 Ubuntu upstream *

References