Lucene search

K
nvd[email protected]NVD:CVE-2014-1402
HistoryMay 19, 2014 - 2:55 p.m.

CVE-2014-1402

2014-05-1914:55:11
CWE-264
web.nvd.nist.gov
3

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.1

Confidence

Low

EPSS

0

Percentile

10.1%

The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with _jinja2 in /tmp.

Affected configurations

Nvd
Node
pocoojinja2Range2.7.1
OR
pocoojinja2Match2.0-
OR
pocoojinja2Match2.0rc1
OR
pocoojinja2Match2.1
OR
pocoojinja2Match2.1.1
OR
pocoojinja2Match2.2
OR
pocoojinja2Match2.2.1
OR
pocoojinja2Match2.3
OR
pocoojinja2Match2.3.1
OR
pocoojinja2Match2.4
OR
pocoojinja2Match2.4.1
OR
pocoojinja2Match2.5
OR
pocoojinja2Match2.5.1
OR
pocoojinja2Match2.5.2
OR
pocoojinja2Match2.5.3
OR
pocoojinja2Match2.5.4
OR
pocoojinja2Match2.5.5
OR
pocoojinja2Match2.6
OR
pocoojinja2Match2.7
VendorProductVersionCPE
pocoojinja2*cpe:2.3:a:pocoo:jinja2:*:*:*:*:*:*:*:*
pocoojinja22.0cpe:2.3:a:pocoo:jinja2:2.0:-:*:*:*:*:*:*
pocoojinja22.0cpe:2.3:a:pocoo:jinja2:2.0:rc1:*:*:*:*:*:*
pocoojinja22.1cpe:2.3:a:pocoo:jinja2:2.1:*:*:*:*:*:*:*
pocoojinja22.1.1cpe:2.3:a:pocoo:jinja2:2.1.1:*:*:*:*:*:*:*
pocoojinja22.2cpe:2.3:a:pocoo:jinja2:2.2:*:*:*:*:*:*:*
pocoojinja22.2.1cpe:2.3:a:pocoo:jinja2:2.2.1:*:*:*:*:*:*:*
pocoojinja22.3cpe:2.3:a:pocoo:jinja2:2.3:*:*:*:*:*:*:*
pocoojinja22.3.1cpe:2.3:a:pocoo:jinja2:2.3.1:*:*:*:*:*:*:*
pocoojinja22.4cpe:2.3:a:pocoo:jinja2:2.4:*:*:*:*:*:*:*
Rows per page:
1-10 of 191

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.1

Confidence

Low

EPSS

0

Percentile

10.1%