Earlier quoted context omitted.
The first two are a third party module. If 0777 is objectionable then I'm surprised you are using the module or haven't at least patched it - not trying to snark, just wondering if there's some additional context. There don't seem to be any specific vulnerabilities related to these permissions, though I'd like to see them go away. It's my understanding that 777 will not exist in Magento 2.
>The first two are a third party module. As I said: Magento Enterprise tar ball, supplied at considerable expense straight from Magento. Magento bears full responsibility for the contents. You really seriously just don't have any excuse for this sort of thing. > There don't seem to be any specific vulnerabilities related to these permissions, though I'd like to see them go away. Only someone working for Magento could…
Re: Magento eCommerce PHP Remote Code Execution
#81Support just confirmed that we do not ship any code in local. Given the namespace I'm assuming your shop works with Gorilla?