Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13185
HistoryJan 15, 2019 - 9:26 a.m.

Insecure File Permissions

2019-01-1509:26:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.001 Low

EPSS

Percentile

26.9%

postgresql uses insecure file permissions. The pg_upgrade module creates a file containing confidential metadata such as database passwords under prevailing umask in the current working directory, which would allow an authenticated user to read or modify the file.

References