PT-2014-3433 · Pallets+2 · Jinja2+2
Thoger
·
Publicado
2014-05-19
·
Atualizado
2024-06-15
·
CVE-2014-0012
CVSS v4.0
6.9
Média
| Vetor | AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Jinja2 version 2.7.2
Jinja2 versions prior to 2.7.2
Description
The FileSystemBytecodeCache in Jinja2 does not properly create temporary directories, allowing local users to gain privileges by pre-creating a temporary directory with a user's uid. This issue exists due to an incomplete fix for a previous problem.
Recommendations
For Jinja2 version 2.7.2, update to a version that properly fixes the temporary directory creation issue.
For Jinja2 versions prior to 2.7.2, update to version 2.7.2 or later to ensure proper temporary directory creation.
As a temporary workaround, consider restricting access to the FileSystemBytecodeCache to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Jinja2
Suse