CVE-2013-2027
published 2015-02-13CVE-2013-2027: Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via…
PriorityP416medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.44%
36.3th percentile
Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jython | < jython 2.7.1+repack-1 (bookworm) | jython 2.7.1+repack-1 (bookworm) |
| jython_project | jython | — | — |
| jython_project | jython | >= 0 < 2.7.1+repack-1 | 2.7.1+repack-1 |
| jython_project | jython | >= 0 < 2.7.1+repack-1 | 2.7.1+repack-1 |
| jython_project | jython | >= 0 < 2.7.1+repack-1 | 2.7.1+repack-1 |
| jython_project | jython | >= 0 < 2.7.1+repack-1 | 2.7.1+repack-1 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6LOW
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Jython creates executables class files with wrong permissions
vendor_redhat·2013-04-03·CVSS 4.6
CVE-2013-2027 [MEDIUM] CWE-732 Jython creates executables class files with wrong permissions
Jython creates executables class files with wrong permissions
Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.
Statement: This issue affects the versions of jython as shipped with Red Hat Enterprise Linux version 5 and 6. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: jython (Red Hat Enterprise Linux 6) - Will not fix
Package: jython (Red Hat JBoss Enterprise Application Platform 6) - Will not fix
Package: jython (Red Hat JBoss SOA Platform 4) - Will not f
Debian
CVE-2013-2027: jython - Jython 2.2.1 uses the current umask to set the privileges of the class cache fil...
vendor_debian·2013·CVSS 4.6
CVE-2013-2027 [MEDIUM] CVE-2013-2027: jython - Jython 2.2.1 uses the current umask to set the privileges of the class cache fil...
Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.7.1+repack-1)
bullseye: resolved (fixed in 2.7.1+repack-1)
forky: resolved (fixed in 2.7.1+repack-1)
sid: resolved (fixed in 2.7.1+repack-1)
trixie: resolved (fixed in 2.7.1+repack-1)
OSV
Jython Improper Access Restrictions vulnerability
osv·2022-05-14
CVE-2013-2027 [MEDIUM] Jython Improper Access Restrictions vulnerability
Jython Improper Access Restrictions vulnerability
Jython before 2.7.2b3 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.
GHSA
Jython Improper Access Restrictions vulnerability
ghsa·2022-05-14
CVE-2013-2027 [MEDIUM] CWE-281 Jython Improper Access Restrictions vulnerability
Jython Improper Access Restrictions vulnerability
Jython before 2.7.2b3 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.
OSV
CVE-2013-2027: Jython 2
osv·2015-02-13·CVSS 4.6
CVE-2013-2027 [MEDIUM] CVE-2013-2027: Jython 2
Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2015-0096.htmlhttp://lists.opensuse.org/opensuse-updates/2015-02/msg00055.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2015:158http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=947949http://advisories.mageia.org/MGASA-2015-0096.htmlhttp://lists.opensuse.org/opensuse-updates/2015-02/msg00055.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2015:158http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=947949
2015-02-13
Published