Back

HIGH

python-paste-script: Supplementary groups not dropped when started an application with "paster serve" as root

Published May 1, 2012

Description

Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published May 1, 2012
Updated Aug 6, 2024
Reserved Jan 19, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Feb 6, 2012
GHSA-27PX-QPMJ-QG38