VDB
Sign up
—

PYSEC-2014-8

Quick fix

PYSEC-2014-8 — jinja2: upgrade to the fixed version with the command below.

pip install --upgrade 'jinja2>=2.7.2'

Details

The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with __jinja2_ in /tmp.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/jinja2
Introduced in: 0Fixed in: 2.7.2
Fixpip install --upgrade 'jinja2>=2.7.2'

References