GHSA-hf4p-4j9r-3cvx

Suggest an improvement
Source
https://github.com/advisories/GHSA-hf4p-4j9r-3cvx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hf4p-4j9r-3cvx/GHSA-hf4p-4j9r-3cvx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hf4p-4j9r-3cvx
Aliases
Published
2022-05-24T22:00:36Z
Modified
2024-04-22T19:05:38Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Incorrect Default Permissions in Beego
Details

The File Session Manager in Beego before 1.12.2 allows local users to read session files because of weak permissions for individual files.

Database specific
{
    "nvd_published_at": "2019-09-16T15:15:00Z",
    "cwe_ids": [
        "CWE-276"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-02-01T21:16:11Z"
}
References

Affected packages

Go / github.com/beego/beego

Package

Name
github.com/beego/beego
View open source insights on deps.dev
Purl
pkg:golang/github.com/beego/beego

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.2

Go / github.com/astaxie/beego

Package

Name
github.com/astaxie/beego
View open source insights on deps.dev
Purl
pkg:golang/github.com/astaxie/beego

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.2