Lucene search

K
osvGoogleOSV:GHSA-8R7Q-CVJQ-X353
HistoryMay 14, 2022 - 4:04 a.m.

Incorrect Privilege Assignment in Jinja2

2022-05-1404:04:14
Google
osv.dev
7
jinja2
privilege assignment
vulnerability
configuration
temporary files
local users
gaining privileges
cache file
/tmp

EPSS

0

Percentile

10.1%

The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with _jinja2 in /tmp.