CVE-2014-0012
Publication date 19 May 2014
Last updated 4 August 2025
Ubuntu priority
FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.
Status
Package | Ubuntu Release | Status |
---|---|---|
jinja2 | 14.04 LTS trusty |
Not affected
|
Notes
mdeslaur
Introduced in 2.7.2, and in CVE-2014-1402 security fix. 2.7.2-2 in trusty switches to tempfile.mkdtemp which fixes the security issue, but isn't an ideal fix for proper caching.
References
Related Ubuntu Security Notices (USN)
- USN-2301-1
- Jinja2 vulnerabilities
- 24 July 2014