Incorrect Default Permissions Affecting docksible package, versions [,0.8.2)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Default Permissions vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-DOCKSIBLE-12671218
  • published16 Sept 2025
  • disclosed1 May 2025
  • creditUnknown

Introduced: 1 May 2025

CVE NOT AVAILABLE CWE-276  (opens in a new tab)

How to fix?

Upgrade docksible to version 0.8.2 or higher.

Overview

docksible is a Deploy and set up Docker Compose based web apps with Ansible

Affected versions of this package are vulnerable to Incorrect Default Permissions via the file permissions of docker-compose files. An attacker could gain unauthorized access to sensitive configuration data or modify service definitions by exploiting overly permissive default permissions. This can lead to unauthorized access to services or exposure of sensitive data.

References

CVSS Base Scores

version 4.0
version 3.1