Files
nuclei-templates/code/macos/audit/insecure-umask.yaml
2025-11-10 09:32:25 +00:00

28 lines
926 B
YAML

id: insecure-umask
info:
name: macOS Permissive Umask Configuration
author: geeknik
severity: medium
description: |
Verifies if the umask is configured with overly permissive values that create insecurely accessible files.
impact: |
A permissive umask can result in new files being created with world-writable permissions, which can be a security risk.
remediation: |
Set the umask to a more restrictive value to ensure that new files are created with secure permissions.
tags: macos,audit,local,security,umask
self-contained: true
code:
- engine:
- sh
- bash
source: |
umask
matchers:
- type: regex
regex:
- "^0?0[0-2][0-7]$"
negative: true
# digest: 4b0a00483046022100c69d262b8d1b34e76e3555fcdba1fae77480c154bd0e30ba8b0acb7e0ed03e3b022100d2c19fc4e134aa384f4498467fe35d921684fe767e0d2948c4f4066cc8491723:922c64590222798bb761d5b6d8e72950