{"id":"GHSA-hf4p-4j9r-3cvx","summary":"Incorrect Default Permissions in Beego","details":"The File Session Manager in Beego before 1.12.2 allows local users to read session files because of weak permissions for individual files.","aliases":["CVE-2019-16354","CVE-2019-16355","GHSA-f6px-w8rh-7r89","GO-2021-0084"],"modified":"2024-04-22T19:05:38Z","published":"2022-05-24T22:00:36Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-02-01T21:16:11Z","nvd_published_at":"2019-09-16T15:15:00Z","cwe_ids":["CWE-276"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-16355"},{"type":"WEB","url":"https://github.com/beego/beego/issues/3763"},{"type":"WEB","url":"https://github.com/beego/beego/pull/3975"},{"type":"WEB","url":"https://github.com/beego/beego/pull/3975/commits/f99cbe0fa40936f2f8dd28e70620c559b6e5e2fd"},{"type":"WEB","url":"https://github.com/beego/beego/commit/bac2b31afecc65d9a89f9e473b8006c5edc0c8d1"}],"affected":[{"package":{"name":"github.com/beego/beego","ecosystem":"Go","purl":"pkg:golang/github.com/beego/beego"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.12.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hf4p-4j9r-3cvx/GHSA-hf4p-4j9r-3cvx.json"}},{"package":{"name":"github.com/astaxie/beego","ecosystem":"Go","purl":"pkg:golang/github.com/astaxie/beego"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.12.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hf4p-4j9r-3cvx/GHSA-hf4p-4j9r-3cvx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}