HIGH7.8
GHSA-vc5p-j8vw-mc6x
Permissions bypass in pleaser
Details
Failure to normalize the umask in pleaser before 0.4.0 allows a local attacker to gain full root privileges if they are allowed to execute at least one command.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/pleaser
Introduced in:
0Fixed in: 0.4.0Upgrade pleaser to 0.4.0 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-31155[ADVISORY]
- https://crates.io/crates/pleaser[WEB]
- https://gitlab.com/edneville/please[WEB]
- https://gitlab.com/edneville/please/-/tree/master/src/bin[WEB]
- https://rustsec.org/advisories/RUSTSEC-2021-0101.html[WEB]
- https://www.openwall.com/lists/oss-security/2021/05/18/1[WEB]