Python rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is used, and thus permissions are not preserved.
{
"github_reviewed": true,
"severity": "HIGH",
"cwe_ids": [
"CWE-276"
],
"nvd_published_at": "2020-06-19T11:15:00Z",
"github_reviewed_at": "2023-08-02T22:38:29Z"
}