High severity7.1NVD Advisory· Published May 30, 2023· Updated Jun 17, 2026
CVE-2023-32698
CVE-2023-32698
Description
nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packaged the files (without extra config for enforcing it’s own permissions) files could go out with bad permissions (chmod 666 or 777). Anyone using nfpm for creating packages without checking/setting file permissions before packaging could result in bad permissions for files/folders.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/goreleaser/nfpm/v2Go | >= 2.0.0, < 2.29.0 | 2.29.0 |
github.com/goreleaser/nfpmGo | >= 0.1.0, <= 1.10.3 | — |
Affected products
6- osv-coords4 versionspkg:apk/chainguard/goreleaser-1.18pkg:apk/wolfi/goreleaser-1.18pkg:golang/github.com/goreleaser/nfpmpkg:golang/github.com/goreleaser/nfpm/v2
< 1.18.2-r12+ 3 more
- (no CPE)range: < 1.18.2-r12
- (no CPE)range: < 1.18.2-r12
- (no CPE)range: >= 0.1.0, <= 1.10.3
- (no CPE)range: >= 2.0.0, < 2.29.0
- goreleaser/nfpmv5Range: >= 2.0.0, < 2.29.0
Patches
Vulnerability mechanics
References
5- github.com/goreleaser/nfpm/commit/ed9abdf63d5012cc884f2a83b4ab2b42b3680d30nvdPatchWEB
- github.com/goreleaser/nfpm/security/advisories/GHSA-w7jw-q4fg-qc4cnvdExploitMitigationVendor AdvisoryWEB
- github.com/advisories/GHSA-w7jw-q4fg-qc4cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-32698ghsaADVISORY
- github.com/goreleaser/nfpm/releases/tag/v2.29.0nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.