Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28335
HistoryDec 06, 2020 - 4:04 a.m.

Insecure Configuration

2020-12-0604:04:38
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
perl
insecure configuration
file-path module
race condition
software
directory-permission loosening logic

EPSS

0.005

Percentile

75.4%

perl allows for insecure configuration. A race condition in the rmtree and remove_tree functions in the File-Path module allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic.