{"id":"GHSA-g28x-pgr3-qqx6","summary":"Octokit gem published with world-writable files","details":"### Impact\n\nVersions [4.23.0](https://rubygems.org/gems/octokit/versions/4.23.0) and [4.24.0](https://rubygems.org/gems/octokit/versions/4.24.0) of the octokit gem were published containing world-writeable files. \n\nSpecifically, the gem was packed with files having their permissions set to `-rw-rw-rw-` (i.e. 0666) instead of `rw-r--r--` (i.e. 0644). This means everyone who is not the owner (Group and Public) with access to the instance where this release had been installed could modify the world-writable files from this gem. \n\nMalicious code already present and running on your machine, separate from this package, could modify the gem’s files and change its behavior during runtime.\n\n### Patches\n* [octokit 4.25.0](https://rubygems.org/gems/octokit/versions/4.25.0)\n\n### Workarounds\nUsers can use the previous version of the gem [v4.22.0](https://rubygems.org/gems/octokit/versions/4.22.0). Alternatively, users can modify the file permissions manually until they are able to upgrade to the latest version.\n\n","aliases":["CVE-2022-31072"],"modified":"2023-11-08T04:09:24.861105Z","published":"2022-06-15T21:24:16Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2022-06-15T21:24:16Z","nvd_published_at":"2022-06-15T23:15:00Z","cwe_ids":["CWE-276"]},"references":[{"type":"WEB","url":"https://github.com/octokit/octokit.rb/security/advisories/GHSA-g28x-pgr3-qqx6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31072"},{"type":"WEB","url":"https://github.com/octokit/octokit.rb/commit/1c8edecc9cf23d1ceb959d91a416a69f55ce7d55"},{"type":"PACKAGE","url":"https://github.com/octokit/octokit.rb"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/octokit/CVE-2022-31072.yml"}],"affected":[{"package":{"name":"octokit","ecosystem":"RubyGems","purl":"pkg:gem/octokit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.23.0"},{"fixed":"4.25.0"}]}],"versions":["4.23.0","4.24.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-g28x-pgr3-qqx6/GHSA-g28x-pgr3-qqx6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}