Security problem with settings and littlefs. Zephyr versions >= 1.14.2, >= 2.3.0 contain Incorrect Default Permissions (CWE-276). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-5qhg-j6wc-4f6q
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-5qhg-j6wc-4f6q | third party advisory |
https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1199 | third party advisory not applicable |