Lucene search

K
githubGitHub Advisory DatabaseGHSA-FQH9-2QGG-H84H
HistoryMay 17, 2022 - 4:01 a.m.

Insecure Temporary File in Jinja2

2022-05-1704:01:00
CWE-377
GitHub Advisory Database
github.com
9
jinja2
temporary file
filesystembytecodecache
vulnerability

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

AI Score

8.4

Confidence

High

EPSS

0

Percentile

10.1%

FileSystemBytecodeCache in Jinja2 prior to version 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user’s uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.

Affected configurations

Vulners
Node
pocoojinja2Range<2.7.2
VendorProductVersionCPE
pocoojinja2*cpe:2.3:a:pocoo:jinja2:*:*:*:*:*:*:*:*

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

AI Score

8.4

Confidence

High

EPSS

0

Percentile

10.1%