CVE-2023-32698
nfpm vulnerable to Incorrect Default Permissions
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.1EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
30 May 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packaged
the files (without extra config for enforcing it’s own permissions) files could go out with bad permissions (chmod 666 or 777). Anyone using nfpm for creating packages without checking/setting file permissions before packaging could result in bad permissions for files/folders.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected products
goreleaser · nfpmWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →