Junglewise Threat Intelligence

CVE-2014-1402: PYSEC-2014-8 - The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows

CVE-2014-1402 · Severity: low · CVSS 3.1 · Published 2014-05-19

Technologies: jinja2 (PyPI). Vendors: PyPI.

Executive brief

The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with __jinja2_ in /tmp.

Affected products

  • PyPI jinja2

Related threats