CVE-2023-32698
nfpm vulnerable to Incorrect Default Permissions
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7.1EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
30 may 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packaged
the files (without extra config for enforcing it’s own permissions) files could go out with bad permissions (chmod 666 or 777). Anyone using nfpm for creating packages without checking/setting file permissions before packaging could result in bad permissions for files/folders.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Productos afectados
goreleaser · nfpm¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →