GCVE-VVD-MAGEIA-2014-28
Advisory Published
Vulnetix · Advisory published February 11, 2014
Updated python-jinja2 packages fix security vulnerability: Jinja2, a template engine written in pure python, was found to use /tmp as a default directory for jinja2.bccache.FileSystemBytecodeCache, which is insecure because the /tmp directory is world-writable and the filenames used like 'FileSystemBytecodeCache' are often predictable. A malicious user could exploit this bug to execute arbitrary code as another user. (CVE-2014-1402)

Affected Products

VendorProductVersionsPlatforms
Mageiapython-jinja20 (affected), 2.5.5-8.2.mga3 (unaffected)
Mageianetworkmanager0 (affected), 0.9.8.8-3.1.mga4 (unaffected)

Aliases

Transitive aliases

References

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.