Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0012

Опубликовано: 11 янв. 2014
Источник: redhat
CVSS2: 4.4
EPSS Низкий

Описание

FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.

Отчет

Not vulnerable. This issue did not affect the versions of python-jinja2 as shipped with Red Hat Enterprise Linux 6 as it did not include the patch that introduced this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6python-jinja2Not affected
Red Hat Enterprise Linux 7python-jinja2Not affected
Red Hat OpenStack Platform 4python-jinja2-26Not affected
Red Hat Software Collectionspython27-python-jinja2Not affected
Red Hat Software Collectionspython33-python-jinja2Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-377
https://bugzilla.redhat.com/show_bug.cgi?id=1052102python-jinja2: FileSystemBytecodeCache insecure cache temporary file use, incorrect CVE-2014-1402 fix

EPSS

Процентиль: 28%
0.00101
Низкий

4.4 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.

nvd
больше 11 лет назад

FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.

debian
больше 11 лет назад

FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create tempo ...

suse-cvrf
больше 10 лет назад

Security update for python-Jinja2

CVSS3: 6.2
github
больше 3 лет назад

Insecure Temporary File in Jinja2

EPSS

Процентиль: 28%
0.00101
Низкий

4.4 Medium

CVSS2