{"id":"GHSA-9347-9w64-q5wp","summary":"Jython Improper Access Restrictions vulnerability","details":"Jython before 2.7.2b3 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.","aliases":["CVE-2013-2027"],"modified":"2024-12-02T05:48:21.443750Z","published":"2022-05-14T02:05:10Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-08-17T22:33:35Z","nvd_published_at":"2015-02-13T15:59:00Z","cwe_ids":["CWE-281"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-2027"},{"type":"WEB","url":"https://github.com/jython/frozen-mirror/commit/053949e66d307168fd70b39725f4d3e6b642acc1"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=947949"},{"type":"WEB","url":"https://github.com/jython/frozen-mirror/blob/b8d7aa4cee50c0c0fe2f4b235dd62922dd0f3f99/NEWS#L25C8-L25C15"},{"type":"WEB","url":"http://advisories.mageia.org/MGASA-2015-0096.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2015-02/msg00055.html"},{"type":"WEB","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2015:158"},{"type":"WEB","url":"http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html"},{"type":"PACKAGE","url":"jython/frozen-mirror"}],"affected":[{"package":{"name":"org.python:jython-standalone","ecosystem":"Maven","purl":"pkg:maven/org.python/jython-standalone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.2b3"}]}],"versions":["2.5.1","2.5.2","2.5.3","2.5.3-rc1","2.5.4-rc1","2.7-b1","2.7-b2","2.7-b3","2.7-b4","2.7-rc1","2.7-rc2","2.7-rc3","2.7.0","2.7.1","2.7.1-rc2","2.7.1-rc3","2.7.1b1","2.7.1b2","2.7.1b3","2.7.2b2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9347-9w64-q5wp/GHSA-9347-9w64-q5wp.json"}}],"schema_version":"1.9.0"}