CVE-2014-1402

Source
https://cve.org/CVERecord?id=CVE-2014-1402
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2014-1402.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2014-1402
Aliases
Downstream
DEBIAN (1)
MGASA (1)
RHSA (2)
UBUNTU (1)
Withdrawn
2026-01-27T04:12:30Z
Published
2014-05-19T14:55:11Z
Modified
2026-04-16T01:48:24Z
Summary
[none]
Details

The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with _jinja2 in /tmp.

References

Affected packages