CVE-2023-32698
Summary
| CVE | CVE-2023-32698 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-30 04:15:00 UTC |
| Updated | 2023-06-06 19:29:00 UTC |
| Description | nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packaged the files (without extra config for enforcing it’s own permissions) files could go out with bad permissions (chmod 666 or 777). Anyone using nfpm for creating packages without checking/setting file permissions before packaging could result in bad permissions for files/folders. |
Risk And Classification
Problem Types: CWE-276
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Goreleaser | Nfpm | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release v2.29.0 · goreleaser/nfpm · GitHub | MISC | github.com | |
| Depending on usage of nfpm could produce CWE-276: Incorrect Default Permissions · Advisory · goreleaser/nfpm · GitHub | MISC | github.com | |
| sec: fix for CVE-2023-32698 · goreleaser/nfpm@ed9abdf · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.