CVE-2014-0012

FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.4 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 27%
Affected Products (NVD)
VendorProductVersion
pocoojinja2
2.7.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jinja2
bookworm
3.1.2-1
fixed
bullseye
2.11.3-1
fixed
sid
3.1.3-1
fixed
squeeze
not-affected
trixie
3.1.3-1
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jinja2
lucid
ignored
precise
Fixed 2.6-1ubuntu0.1
released
quantal
ignored
raring
ignored
saucy
ignored
trusty
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
python2-Jinja2
suse enterprise desktop 15
2.10-1.21
fixed
suse enterprise sap 15
2.10-1.21
fixed
suse enterprise server 15
2.10-1.21
fixed
python3-Jinja2
suse enterprise desktop 15
2.10-1.21
fixed
suse enterprise sap 15
2.10-1.21
fixed
suse enterprise server 15
2.10-1.21
fixed
Common Weakness Enumeration