Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-53945

Опубликовано: 18 июл. 2025
Источник: nvd
CVSS3: 7
EPSS Низкий

Описание

apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. Version 0.29.5 contains a fix for the issue.

EPSS

Процентиль: 3%
0.00017
Низкий

7 High

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 7
github
7 месяцев назад

apko is vulnerable to attack through incorrect permissions in /etc/ld.so.cache and other files

EPSS

Процентиль: 3%
0.00017
Низкий

7 High

CVSS3

Дефекты

CWE-276