create TUF cache directories with restrictive permissions
fixed in public source; rollout not reverified
details
Finding IDs
F-TUF-002
Status
fixed in public source; rollout not reverified
Disclosure date
Note
PR #714 creates cache directories with mode 0700 instead of os.ModePerm. The change does not repair permissions on already-existing directories. This is the go-tuf cache-permission finding, not python-tuf bootstrap PR #2903. Release inclusion was not independently checked.
F-TUF-002: Access control. Cache-file permissions permit unintended local access. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Security area (1seal assessment): Authorization. Restrictive creation permissions prevent other local users from modifying newly created cache directories. Reviewed 23 Sep 2026.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.