CVE-2019-16355: Incorrect Default Permissions in Beego
5.5
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.12695%
CWE
Published
5/24/2022
Updated
4/22/2024
KEV Status
No
Technology
Go
Technical Details
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/beego/beego | go | < 1.12.2 | 1.12.2 |
| github.com/astaxie/beego | go | < 1.12.2 | 1.12.2 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability stems from directory creation with insecure 0777 permissions in session management. The commit f99cbe0 shows these functions were patched by changing permissions from 0777 to 0755. Both functions handle session storage directory creation, and the original 0777 mode allowed any local user to read session files. The CWE-276 mapping confirms this is an incorrect default permissions issue.