Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26198
HistoryAug 06, 2020 - 9:35 p.m.

Insecure File Permissions

2020-08-0621:35:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19
php7
file permissions
phar archives
insecure
local user

EPSS

0.006

Percentile

78.7%

PHP7 uses insecure file permissions. When creating PHAR archives using the PharData::buildFromIterator() function, the files are added with default permissions (0666) even if the original files on the filesystem configured with more restrictive permissions, allowing any local user to access the files.