← back
CVE-2023-32698

nfpm vulnerable to Incorrect Default Permissions

CVSS 7.1 HIGHEPSS 0.4%CWE-276
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.1EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
30 May 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packaged the files (without extra config for enforcing it’s own permissions) files could go out with bad permissions (chmod 666 or 777). Anyone using nfpm for creating packages without checking/setting file permissions before packaging could result in bad permissions for files/folders.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected products
goreleaser · nfpm

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →