VDB
KO

PYSEC-2014-8

Details

The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with __jinja2_ in /tmp.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / jinja2
Introduced in: 0 Fixed in: 2.7.2
Fix pip install --upgrade 'jinja2>=2.7.2'

References