VYPR
High severity7.1NVD Advisory· Published May 30, 2023· Updated Jun 17, 2026

CVE-2023-32698

CVE-2023-32698

Description

nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packaged the files (without extra config for enforcing it’s own permissions) files could go out with bad permissions (chmod 666 or 777). Anyone using nfpm for creating packages without checking/setting file permissions before packaging could result in bad permissions for files/folders.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/goreleaser/nfpm/v2Go
>= 2.0.0, < 2.29.02.29.0
github.com/goreleaser/nfpmGo
>= 0.1.0, <= 1.10.3

Affected products

6

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.