CVE Vulnerabilities

CVE-2014-1402

Published: May 19, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
4.4 MODERATE
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with _jinja2 in /tmp.

Affected Software

NameVendorStart VersionEnd Version
Jinja2Pocoo*2.7.1 (including)
Jinja2Pocoo2.0 (including)2.0 (including)
Jinja2Pocoo2.0-rc1 (including)2.0-rc1 (including)
Jinja2Pocoo2.1 (including)2.1 (including)
Jinja2Pocoo2.1.1 (including)2.1.1 (including)
Jinja2Pocoo2.2 (including)2.2 (including)
Jinja2Pocoo2.2.1 (including)2.2.1 (including)
Jinja2Pocoo2.3 (including)2.3 (including)
Jinja2Pocoo2.3.1 (including)2.3.1 (including)
Jinja2Pocoo2.4 (including)2.4 (including)
Jinja2Pocoo2.4.1 (including)2.4.1 (including)
Jinja2Pocoo2.5 (including)2.5 (including)
Jinja2Pocoo2.5.1 (including)2.5.1 (including)
Jinja2Pocoo2.5.2 (including)2.5.2 (including)
Jinja2Pocoo2.5.3 (including)2.5.3 (including)
Jinja2Pocoo2.5.4 (including)2.5.4 (including)
Jinja2Pocoo2.5.5 (including)2.5.5 (including)
Jinja2Pocoo2.6 (including)2.6 (including)
Jinja2Pocoo2.7 (including)2.7 (including)
Red Hat Enterprise Linux 6RedHatpython-jinja2-0:2.2.1-2.el6_5*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6RedHatpython27-python-jinja2-0:2.6-10.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6RedHatpython33-python-jinja2-0:2.6-11.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.3 EUSRedHatpython27-python-jinja2-0:2.6-10.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.3 EUSRedHatpython33-python-jinja2-0:2.6-11.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUSRedHatpython27-python-jinja2-0:2.6-10.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUSRedHatpython33-python-jinja2-0:2.6-11.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7RedHatpython27-python-jinja2-0:2.6-11.el7*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7RedHatpython33-python-jinja2-0:2.6-12.el7*
Jinja2Ubuntulucid*
Jinja2Ubuntuprecise*
Jinja2Ubuntuquantal*
Jinja2Ubunturaring*
Jinja2Ubuntusaucy*
Jinja2Ubuntuupstream*

References