apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. Version 0.29.5 contains a fix for the issue.
History

Tue, 22 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Jul 2025 15:45:00 +0000

Type Values Removed Values Added
Description apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. Version 0.29.5 contains a fix for the issue.
Title apko has incorrect permission (0666) in /etc/ld.so.cache and other files
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-18T15:35:17.325Z

Updated: 2025-07-22T15:03:42.966Z

Reserved: 2025-07-14T17:23:35.262Z

Link: CVE-2025-53945

cve-icon Vulnrichment

Updated: 2025-07-22T15:03:39.488Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-18T16:15:30.020

Modified: 2025-07-22T13:06:27.983

Link: CVE-2025-53945

cve-icon Redhat

No data.