Intel

AIKIDO-2024-10540

pyngrok is vulnerable to Incorrect Permission Assignment for Critical Resource

Incorrect Permission Assignment for Critical Resource Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 16, 2024

60

Medium Risk

This Affects:

pythonpyngrok
0.1.2 - 7.2.1
Fixed in 7.2.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package apply overly permissive 777 permissions to the installed binary, allowing execute access for all users. The patched version resolves this issue by restricting execute permissions to the binary's owner, improving overall security.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

pyngrok is vulnerable to Incorrect Permission Assignment for Critical Resource in versions 0.1.2 - 7.2.1.

How to fix this

Upgrade the pyngrok library to the patch version.