CVE-2019-16355

Incorrect Default Permissions in go/github.com/beego/beego

Identifiers

GHSA-hf4p-4j9r-3cvx, CVE-2019-16355

Package Slug

go/github.com/beego/beego

Vulnerability

Incorrect Default Permissions

Description

The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for individual files.

Affected Versions

All versions before 1.12.2

Solution

Upgrade to version 1.12.2 or above.

Last Modified

2024-02-02

source