{"id":"CVE-2022-31071","aliases":["GHSA-26qj-cr27-r5c4"],"url":"https://o3.security/vulnerability/CVE-2022-31071","summary":"Octopoller gem published with world-writable files","details":"### Impact\n\nVersion [0.2.0](https://rubygems.org/gems/octopoller/versions/0.2.0) of the octopoller gem was published containing world-writeable files. Specifically, the gem was packed with files having their permissions set to `-rw-rw-rw-` (i.e. 0666) instead of `rw-r--r--` (i.e. 0644). \n\nThis means everyone who is not the owner (Group and Public) with access to the instance where this release had been installed could modify the world-writable files from this gem. \n\nMalicious code already present and running on your machine, separate from this package, could modify the gem’s files and change its behavior during runtime.\n\n### Patches\n* octopoller 0.3.0\n\n### Workarounds\nUsers can use the previous version of the gem [v0.1.0](https://rubygems.org/gems/octopoller/versions/0.1.0). Alternatively, users can modify the file permissions manually until they are able to upgrade to the latest version.\n\n","published":"2022-06-15T22:35:15Z","modified":"2026-08-12T03:51:11.036633409Z","cvss":{"score":2.5,"severity":"LOW","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"octopoller","fixedVersion":"0.3.0"}],"fix":{"url":"https://github.com/octokit/octopoller.rb/commit/abed2b8d05abe2cc3eb6bdfb34e53d465e7c7874","label":"octokit/octopoller.rb@abed2b8"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/31xxx/CVE-2022-31071.json"},{"type":"ADVISORY","url":"https://github.com/octokit/octopoller.rb/security/advisories/GHSA-26qj-cr27-r5c4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31071"},{"type":"FIX","url":"https://github.com/octokit/octopoller.rb/commit/abed2b8d05abe2cc3eb6bdfb34e53d465e7c7874"},{"type":"PACKAGE","url":"https://github.com/octokit/octopoller"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/octopoller/CVE-2022-31071.yml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:11.036633409Z"}}