A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process before the files are loaded in BigQuery. We recommend upgrading to version 1.0.3 or above.
Weaknesses in this category are related to improper assignment or handling of permissions.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://github.com/google/sa360-webquery-bigquery/pull/15 | third party advisory patch |
https://github.com/google/sa360-webquery-bigquery/releases/tag/v1.0.3 | third party advisory release notes |
https://github.com/JLLeitschuh/security-research/security/advisories/GHSA-7fjx-657r-9r5h | third party advisory |