CVE-2014-0012: Medium severity Pocoo Jinja2 vulnerability
FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.
Other sources
FileSystemBytecodeCache in Jinja2 prior to version 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0012?
CVE-2014-0012 is considered a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2014-0012?
To fix CVE-2014-0012, upgrade Jinja2 to a version later than 2.7.2 where this vulnerability has been addressed.
Who is affected by CVE-2014-0012?
Users of Jinja2 version 2.7.2 are affected by CVE-2014-0012.
What type of attack does CVE-2014-0012 facilitate?
CVE-2014-0012 facilitates local privilege escalation attacks.
Is CVE-2014-0012 a result of previous vulnerabilities?
Yes, CVE-2014-0012 is a result of an incomplete fix for CVE-2014-1402.