PT-2014-3433 · Pallets+2 · Jinja2+2

Thoger

·

Published

2014-05-19

·

Updated

2024-06-15

·

CVE-2014-0012

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Jinja2 version 2.7.2 Jinja2 versions prior to 2.7.2
Description The FileSystemBytecodeCache in Jinja2 does not properly create temporary directories, allowing local users to gain privileges by pre-creating a temporary directory with a user's uid. This issue exists due to an incomplete fix for a previous problem.
Recommendations For Jinja2 version 2.7.2, update to a version that properly fixes the temporary directory creation issue. For Jinja2 versions prior to 2.7.2, update to version 2.7.2 or later to ensure proper temporary directory creation. As a temporary workaround, consider restricting access to the FileSystemBytecodeCache to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3106
ALT-PU-2024-3036
CVE-2014-0012
GHSA-FQH9-2QGG-H84H
OPENSUSE-SU-2016_2465-1
OPENSUSE-SU-2019:0244-1
OPENSUSE-SU-2024:10129-1
OPENSUSE-SU-2024:11208-1
OPENSUSE-SU-2024:13930-1
PYSEC-2014-82
SUSE-FU-2022:0444-1
SUSE-FU-2022:0445-1
SUSE-SU-2015:1336-1
USN-2301-1

Affected Products

Alt Linux
Jinja2
Suse