-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from directory creation with insecure 0777 permissions in session management. The commit f99cbe0 shows these functions were patched by changing permissions from 0777 to 0755. Both functions handle session storage directory creation, and the original 0777 mode allowed any local user to read session files. The CWE-276 mapping confirms this is an incorrect default permissions issue.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/beego/beego | go | < 1.12.2 | 1.12.2 |
| github.com/astaxie/beego | go | < 1.12.2 | 1.12.2 |
Ongoing coverage of React2Shell