CVE-2014-1402

medium
Published 2014-05-19 · Modified 2023-11-08
CVSS v3
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
4.4
VIR risk
4.4

Description

The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with __jinja2_ in /tmp.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-1402

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.7.2-1
debian debianbullseyefixed2.7.2-1
debian debianforkyfixed2.7.2-1
debian debiansidfixed2.7.2-1
debian debiantrixiefixed2.7.2-1

Package impact

EcosystemPackageVulnerableFixed
python PyPIjinja2<2.7.22.7.2

Application impact

VendorProductVersionsFixed
pocoojinja2{"endIncluding":"2.7.1"}
pocoojinja22.0
pocoojinja22.1
pocoojinja22.1.1
pocoojinja22.2
pocoojinja22.2.1
pocoojinja22.3
pocoojinja22.3.1
pocoojinja22.4
pocoojinja22.4.1
pocoojinja22.5
pocoojinja22.5.1
pocoojinja22.5.2
pocoojinja22.5.3
pocoojinja22.5.4
pocoojinja22.5.5
pocoojinja22.6
pocoojinja22.7

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.