GHSA-g28x-pgr3-qqx6
Dashboard / Vulnerabilities / GHSA-g28x-pgr3-qqx6
Summary: Octokit gem published with world-writable files
Details: ### Impact Versions [4.23.0](https://rubygems.org/gems/octokit/versions/4.23.0) and [4.24.0](https://rubygems.org/gems/octokit/versions/4.24.0) of the octokit gem were published containing world-writeable files. Specifically, the gem was packed with files having their permissions set to `-rw-rw-rw-` (i.e. 0666) instead of `rw-r--r--` (i.e. 0644). This means everyone who is not the owner (Group and Public) with access to the instance where this release had been installed could modify the world-writable files from this gem. Malicious code already present and running on your machine, separate from this package, could modify the gem’s files and change its behavior during runtime. ### Patches * [octokit 4.25.0](https://rubygems.org/gems/octokit/versions/4.25.0) ### Workarounds Users can use the previous version of the gem [v4.22.0](https://rubygems.org/gems/octokit/versions/4.22.0). Alternatively, users can modify the file permissions manually until they are able to upgrade to the latest version.
References: https://github.com/octokit/octokit.rb/security/advisories/GHSA-g28x-pgr3-qqx6, https://nvd.nist.gov/vuln/detail/CVE-2022-31072, https://github.com/octokit/octokit.rb/commit/1c8edecc9cf23d1ceb959d91a416a69f55ce7d55, https://github.com/octokit/octokit.rb, https://github.com/rubysec/ruby-advisory-db/blob/master/gems/octokit/CVE-2022-31072.yml
Affected packages
Package
Name: octokit
Purl: pkg:gem/octokit
Affected ranges
Type: ECOSYSTEM
Events:
