Python keyring lib before 0.10 created keyring files with world-readable permissions.
{ "severity": "HIGH", "cwe_ids": [ "CWE-276" ], "github_reviewed": true, "github_reviewed_at": "2020-03-11T21:36:23Z", "nvd_published_at": null }