← volver
CVE-2023-32698

nfpm vulnerable to Incorrect Default Permissions

CVSS 7.1 HIGHEPSS 0.4%CWE-276
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 7.1EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
30 may 2023Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packaged the files (without extra config for enforcing it’s own permissions) files could go out with bad permissions (chmod 666 or 777). Anyone using nfpm for creating packages without checking/setting file permissions before packaging could result in bad permissions for files/folders.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Productos afectados
goreleaser · nfpm

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →