Description
The File Session Manager in Beego 1.10.0 allows local users to read session files because there is a race condition involving file creation within a directory with weak permissions.
Remediation
References
Related Vulnerabilities
TYPO3 Other Vulnerability (CVE-2009-3630)
Ruby Numeric Errors Vulnerability (CVE-2009-1904)
WordPress Plugin PWG Random Cross-Site Request Forgery (1.11)
Atlassian Confluence Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-29450)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-3007)