CVE-2014-0012
published 2014-05-19CVE-2014-0012: FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary…
PriorityP416medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.43%
35.2th percentile
FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jinja2 | < jinja2 2.7.2-2 (bookworm) | jinja2 2.7.2-2 (bookworm) |
| pocoo | jinja2 | — | — |
| pocoo | jinja2 | >= 0 < 2.7.2-2 | 2.7.2-2 |
| pocoo | jinja2 | >= 0 < 2.7.2-2 | 2.7.2-2 |
| pocoo | jinja2 | >= 0 < 2.7.2-2 | 2.7.2-2 |
| pocoo | jinja2 | >= 0 < 2.7.2-2 | 2.7.2-2 |
| pocoo | jinja2 | >= 0 < 2.7.2 | 2.7.2 |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
ghsa4.4MEDIUM
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Insecure Temporary File in Jinja2
osv·2022-05-17·CVSS 4.4
CVE-2014-0012 [MEDIUM] Insecure Temporary File in Jinja2
Insecure Temporary File in Jinja2
FileSystemBytecodeCache in Jinja2 prior to version 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.
GHSA
Insecure Temporary File in Jinja2
ghsa·2022-05-17·CVSS 4.4
CVE-2014-0012 [MEDIUM] CWE-377 Insecure Temporary File in Jinja2
Insecure Temporary File in Jinja2
FileSystemBytecodeCache in Jinja2 prior to version 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.
OSV
CVE-2014-0012: FileSystemBytecodeCache in Jinja2 2
osv·2014-05-19·CVSS 4.4
CVE-2014-0012 [MEDIUM] CVE-2014-0012: FileSystemBytecodeCache in Jinja2 2
FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.
Ubuntu
Jinja2 vulnerabilities
vendor_ubuntu·2014-07-24
CVE-2014-0012 Jinja2 vulnerabilities
Title: Jinja2 vulnerabilities
Summary: A security issue was fixed in Jinja2.
It was discovered that Jinja2 incorrectly handled temporary cache files and
directories. A local attacker could use this issue to possibly gain
privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-jinja2: FileSystemBytecodeCache insecure cache temporary file use, incorrect CVE-2014-1402 fix
vendor_redhat·2014-01-11·CVSS 4.4
CVE-2014-0012 [MEDIUM] CWE-377 python-jinja2: FileSystemBytecodeCache insecure cache temporary file use, incorrect CVE-2014-1402 fix
python-jinja2: FileSystemBytecodeCache insecure cache temporary file use, incorrect CVE-2014-1402 fix
FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.
Statement: Not vulnerable. This issue did not affect the versions of python-jinja2 as shipped with Red Hat Enterprise Linux 6 as it did not include the patch that introduced this flaw.
Package: python-jinja2 (Red Hat Enterprise Linux 6) - Not affected
Package: python-jinja2 (Red Hat Enterprise Linux 7) - Not affected
Package: python-jinja2-26 (Red Hat OpenStack Platform 4) - Not affected
Package: python27-python-jinja2
Debian
CVE-2014-0012: jinja2 - FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary direc...
vendor_debian·2014·CVSS 4.4
CVE-2014-0012 [MEDIUM] CVE-2014-0012: jinja2 - FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary direc...
FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.
Scope: local
bookworm: resolved (fixed in 2.7.2-2)
bullseye: resolved (fixed in 2.7.2-2)
forky: resolved (fixed in 2.7.2-2)
sid: resolved (fixed in 2.7.2-2)
trixie: resolved (fixed in 2.7.2-2)
No detection rules found.
Bugzilla
CVE-2014-0012 python-jinja2: FileSystemBytecodeCache insecure cache temporary file use, incorrect CVE-2014-1402 fix
bugzilla·2014-01-13·CVSS 4.4
CVE-2014-0012 [MEDIUM] CVE-2014-0012 python-jinja2: FileSystemBytecodeCache insecure cache temporary file use, incorrect CVE-2014-1402 fix
CVE-2014-0012 python-jinja2: FileSystemBytecodeCache insecure cache temporary file use, incorrect CVE-2014-1402 fix
An insecure temporary file creation vulnerability was introduced in Jinja2 in the fix for CVE-2014-1402 through the commit:
https://github.com/mitsuhiko/jinja2/commit/acb672b6a179567632e032f547582f30fa2f4aa7
References:
http://seclists.org/oss-sec/2014/q1/73
Discussion:
Acknowledgement:
This issue was discovered by Arun Babu Neelicattu of the Red Hat Security Response Team.
---
Statement:
Not vulnerable. This issue did not affect the versions of python-jinja2 as shipped with Red Hat Enterprise Linux 6 as it did not include the patch that introduced this flaw.
---
This issue has pretty much identical impact to the original issue - file overwrites typical for temporar
Bugzilla
CVE-2014-1402 python-jinja2: FileSystemBytecodeCache insecure cache temporary file use
bugzilla·2014-01-10·CVSS 4.4
CVE-2014-1402 [MEDIUM] CVE-2014-1402 python-jinja2: FileSystemBytecodeCache insecure cache temporary file use
CVE-2014-1402 python-jinja2: FileSystemBytecodeCache insecure cache temporary file use
Jinja2, a template engine written in pure python, was found to use /tmp as a default directory for jinja2.bccache.FileSystemBytecodeCache, which is insecure because the /tmp directory is world-writable and the filenames used by FileSystemBytecodeCache are predictable. A malicious local user could exploit this bug to alter output generated by other user's application using Jinja2 or possibly, execute arbitrary code as another user.
References:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=734747
Discussion:
Created python-jinja2 tracking bugs for this issue:
Affects: fedora-all [bug 1051424]
Affects: epel-all [bug 1051425]
---
Created python26-jinja2 tracking bugs for this issue:
Affects: epel-
http://seclists.org/oss-sec/2014/q1/73http://secunia.com/advisories/56328http://secunia.com/advisories/60738http://www.gentoo.org/security/en/glsa/glsa-201408-13.xmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1051421https://github.com/mitsuhiko/jinja2/commit/acb672b6a179567632e032f547582f30fa2f4aa7https://github.com/mitsuhiko/jinja2/pull/292https://github.com/mitsuhiko/jinja2/pull/296http://seclists.org/oss-sec/2014/q1/73http://secunia.com/advisories/56328http://secunia.com/advisories/60738http://www.gentoo.org/security/en/glsa/glsa-201408-13.xmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1051421https://github.com/mitsuhiko/jinja2/commit/acb672b6a179567632e032f547582f30fa2f4aa7https://github.com/mitsuhiko/jinja2/pull/292https://github.com/mitsuhiko/jinja2/pull/296
2014-05-19
Published