VulnerabilityModified
CVE-2013-2027
Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.
MEDIUM 4.6EPSS 0.44%
Does this matter?
Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.
Description
Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.44% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- opensuse/opensuse · jython project/jython
- Source
- secalert@redhat.com
References
- http://advisories.mageia.org/MGASA-2015-0096.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00055.htmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:158Broken Link
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- https://bugzilla.redhat.com/show_bug.cgi?id=947949Issue Tracking
- http://advisories.mageia.org/MGASA-2015-0096.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00055.htmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:158Broken Link
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- https://bugzilla.redhat.com/show_bug.cgi?id=947949Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.