Back

HIGH

python-jinja2: FileSystemBytecodeCache insecure cache temporary file use

Published May 19, 2014

Description

The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with __jinja2_ in /tmp.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (23)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 19, 2014
Updated Aug 6, 2024
Reserved Jan 10, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 9, 2014
GHSA-8R7Q-CVJQ-X353