T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:6- Finding
Plaintext Log Files Are Created Without Restrictive Permissions
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh:6-9, with user-input write operations repeated atscripts/script.sh:139-310
Vulnerability Type: Insecure local storage and insufficient file permissions
Risk Level: MediumVulnerable Code
bash DATA_DIR="${HOME}/.local/share/calctool" mkdir -p "$DATA_DIR" _log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }A representative user-input write operation is:
bash local input="$*" local ts=$(date '+%Y-%m-%d %H:%M') echo "$ts|$input" >> "$DATA_DIR/run.log" echo " [Calctool] run: $input" _log "run" "$input"Equivalent plaintext writes appear in the
check,convert,analyze,generate,preview,batch,compare,export,config,status, andreportcommand branches.Technical Analysis
The script creates its data directory and log files without setting a restrictive
umaskor explicitly enforcing owner-only permissions. Consequently, permissions depend on the invoking environment's currentumask. Under common defaults, the directory may be created as mode0755and log files as mode0644, allowing other local users to traverse the directory and read recorded content.The logged values are supplied directly by users and may include financial calculations, configuration details, operational status information, reports, or other sensitive data. The same value is also copied into
history.log, increasing the number of locations containing the information. The files are persistent and no retention, redaction, or automatic deletion mechanism is implemented.The script currently also uses
localoutside functions in the command-dispatch branches, which causes standard Bash executions of those branches to fail before their intended writes. This is a correctness defect that limits immediate reachability of the vulnerable write paths in the present version. Nevertheless, the storage impl ...[truncated 1411 chars]- Remediation
View remediation
Remediation Suggestions
-
Set a restrictive file-creation mask before creating any storage:
bash umask 077 -
Create and verify the data directory with owner-only permissions:
bash mkdir -p "$DATA_DIR" chmod 700 "$DATA_DIR" -
Explicitly create log files with mode
0600before appending data:bash install -m 600 /dev/null "$DATA_DIR/history.log"Existing files should be checked and corrected with
chmod 600. -
Avoid logging sensitive values by default. Provide an explicit opt-in for persistent logging and redact credentials, tokens, account identifiers, and confidential financial data.
-
Add retention controls, including commands to securely remove old records and documentation explaining where data is stored and how long it remains.
-
Correct the top-level
localdeclarations by moving command logic into functions or replacing those declarations with normal assignments. Apply and test the permission hardening before making the currently failing write paths operational. -
Add automated tests that execute the tool under a permissive parent
umaskand verify that the resulting directory is mode0700and every data file is mode0600.
-
