CVE-2014-0012
Publication date 19 May 2014
Last updated 4 August 2025
Ubuntu priority
Description
FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.
Status
| Package | Ubuntu Release | Status | 
|---|---|---|
| jinja2 | 14.04 LTS trusty | 
                                Not affected 
                                
                               | 
Notes
mdeslaur
Introduced in 2.7.2, and in CVE-2014-1402 security fix. 2.7.2-2 in trusty switches to tempfile.mkdtemp which fixes the security issue, but isn't an ideal fix for proper caching.
References
Related Ubuntu Security Notices (USN)
- USN-2301-1
- Jinja2 vulnerabilities
- 24 July 2014