CVE Feed

    Dashboard / CVE / CVE-2023-32698

    CVE-2023-32698

    nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packaged the files (without extra config for enforcing it’s own permissions) files could go out with bad permissions (chmod 666 or 777). Anyone using nfpm for creating packages without checking/setting file permissions before packaging could result in bad permissions for files/folders.

    Published:May 30, 2023
    Last Modified:Jan 10, 2025
    EPS:May 30, 2023
    EPSS Score:0.0018
    CVSS Score:7.1

    Affected Products

    Vendor
    Goreleaser
    Product
    Nfpm

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High