First published: Mon May 19 2014(Updated: )
FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
pip/Jinja2 | <2.7.2 | 2.7.2 |
Python Jinja2 | =2.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0012 is considered a high severity vulnerability due to its potential for privilege escalation.
To fix CVE-2014-0012, upgrade Jinja2 to a version later than 2.7.2 where this vulnerability has been addressed.
Users of Jinja2 version 2.7.2 are affected by CVE-2014-0012.
CVE-2014-0012 facilitates local privilege escalation attacks.
Yes, CVE-2014-0012 is a result of an incomplete fix for CVE-2014-1402.