melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version 0.29.5, SBOM files generated by melange in apks had file system permissions mode 666. This potentially allows an unprivileged user to tamper with apk SBOMs on a running image, potentially confusing security scanners. An attacker could also perform a DoS under special circumstances. Version 0.29.5 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 18 Jul 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 18 Jul 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | melange allows users to build apk packages using declarative pipelines. Starting in version 0.23.0 and prior to version 0.29.5, SBOM files generated by melange in apks had file system permissions mode 666. This potentially allows an unprivileged user to tamper with apk SBOMs on a running image, potentially confusing security scanners. An attacker could also perform a DoS under special circumstances. Version 0.29.5 fixes the issue. | |
Title | melange creates SBOM files in APKs with world-writable permissions | |
Weaknesses | CWE-276 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-18T15:40:43.277Z
Updated: 2025-07-18T16:04:30.154Z
Reserved: 2025-07-16T13:22:18.203Z
Link: CVE-2025-54059

Updated: 2025-07-18T15:53:59.807Z

Status : Awaiting Analysis
Published: 2025-07-18T16:15:30.180
Modified: 2025-07-22T13:06:27.983
Link: CVE-2025-54059

No data.