luigi is vulnerable to Incorrect Permission Assignment
77
High Risk
Affected versions of this package set overly permissive file permissions in luigi/lock.py, setting the file permissions of the pid_dir directory to 0o777 in the acquire_for function. On POSIX systems, file permissions should be strictly limited to prevent unauthorized access by other users. However, these permissive settings allow others to access the file's contents, creating a potential security risk. This issue could also be exploited to write or execute malicious code, potentially leading to privilege escalation.
You are affected if you are using a version that falls within the vulnerable range.
luigi is vulnerable to Incorrect Permission Assignment in versions 1.0.17 - 3.5.1.
Upgrade the luigi library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant