GHSA-26qj-cr27-r5c4
Dashboard / Vulnerabilities / GHSA-26qj-cr27-r5c4
Summary: Octopoller gem published with world-writable files
Details: ### Impact Version [0.2.0](https://rubygems.org/gems/octopoller/versions/0.2.0) of the octopoller gem was published containing world-writeable files. Specifically, the gem was packed with files having their permissions set to `-rw-rw-rw-` (i.e. 0666) instead of `rw-r--r--` (i.e. 0644). This means everyone who is not the owner (Group and Public) with access to the instance where this release had been installed could modify the world-writable files from this gem. Malicious code already present and running on your machine, separate from this package, could modify the gem’s files and change its behavior during runtime. ### Patches * octopoller 0.3.0 ### Workarounds Users can use the previous version of the gem [v0.1.0](https://rubygems.org/gems/octopoller/versions/0.1.0). Alternatively, users can modify the file permissions manually until they are able to upgrade to the latest version.
References: https://github.com/octokit/octopoller.rb/security/advisories/GHSA-26qj-cr27-r5c4, https://nvd.nist.gov/vuln/detail/CVE-2022-31071, https://github.com/octokit/octopoller.rb/commit/abed2b8d05abe2cc3eb6bdfb34e53d465e7c7874, https://github.com/octokit/octopoller, https://github.com/rubysec/ruby-advisory-db/blob/master/gems/octopoller/CVE-2022-31071.yml
Affected packages
Package
Name: octopoller
Purl: pkg:gem/octopoller
Affected ranges
Type: ECOSYSTEM
Events:
