Lucene search

K
osvGoogleOSV:GHSA-FQH9-2QGG-H84H
HistoryMay 17, 2022 - 4:01 a.m.

Insecure Temporary File in Jinja2

2022-05-1704:01:00
Google
osv.dev
2
jinja2
temporary file
filesystembytecodecache
local users
privileges
vulnerability

EPSS

0

Percentile

10.1%

FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user’s uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.