Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2012-0878

20
FAUCET Score

CVE-2012-0878 describes a privilege escalation vulnerability in Paste Script 1.7.5 and earlier, affecting the pythonpaste and paste products. This flaw allows remote attackers to bypass file-access restrictions when a web application utilizes the local filesystem and Paste Script executes with root privileges, due to improper group membership settings. While rated with a CVSS score of 5.1 (medium severity) indicating network access, high attack complexity, and partial impact on confidentiality, integrity, and availability, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.7.5CPE matchmatch criteria
cpe:2.3:a:pythonpaste:paste:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.1MEDIUM

AV:N/AC:H/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
4.9
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
4.04%
Probability of exploitation in next 30 days
EPSS Percentile
89.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0404 is in the 86th percentile among its peer group of 19,954 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

pippatch availablevia ghsa
Product: pastescriptFixed in: 2.0.1
pippatch availablevia ghsa
Product: pasteFixed in: 1.7.5.1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: python-paste-script-0:1.7.3-5.el6_3
View patch

Vendor Advisories (2)

pipGHSA-27px-qpmj-qg38high

Paste Script has improper group memberships permissions

May 17, 2022
redhatCVE-2012-0878Moderate

python-paste-script: Supplementary groups not dropped when started an application with "paster serve" as root

Feb 6, 2012

References

groups.google.com / group/paste-users/browse_thread/thread/2aa651ba331c2471
rhn.redhat.com / errata/RHSA-2012-1206.html
bitbucket.org / ianb/pastescript/changeset/a19e462769b4
Patch
bitbucket.org / ianb/pastescript/pull-request/3/fix-group-permissions-for-pastescriptserve
Patch
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/48812
secunia.com / advisories/50410
openwall.com / lists/oss-security/2012/02/23/1
Patch
openwall.com / lists/oss-security/2012/02/23/4