Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command.
{ "nvd_published_at": "2021-05-27T13:15:00Z", "github_reviewed_at": "2021-06-01T19:29:53Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-269", "CWE-279" ] }