CVE-2014-1402: Pocoo JINJA2

Medium severity, CVSS 4.4. EPSS: 0.4% chance of exploitation in the next 30 days.

The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with __jinja2_ in /tmp.

Affected products

  • Pocoo JINJA2: up to and including 2.7.1; version 2.0 only; version 2.1 only; version 2.1.1 only; version 2.2 only; version 2.2.1 only; …

Published 2014-05-19. Last modified 2026-06-17.