CVE-2012-0878: Pythonpaste Paste

Medium severity, CVSS 5.1. EPSS: 4% chance of exploitation in the next 30 days.

Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem.

Affected products

Published 2012-05-01. Last modified 2026-06-16.