apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. Version 0.29.5 contains a fix for the issue.
Metrics
Affected Vendors & Products
References
History
Tue, 22 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 18 Jul 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. Version 0.29.5 contains a fix for the issue. | |
Title | apko has incorrect permission (0666) in /etc/ld.so.cache and other files | |
Weaknesses | CWE-276 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-18T15:35:17.325Z
Updated: 2025-07-22T15:03:42.966Z
Reserved: 2025-07-14T17:23:35.262Z
Link: CVE-2025-53945

Updated: 2025-07-22T15:03:39.488Z

Status : Awaiting Analysis
Published: 2025-07-18T16:15:30.020
Modified: 2025-07-22T13:06:27.983
Link: CVE-2025-53945

No data.