It was found that the private key for the node certificate was contained in a world-readable file. A local user could possibly use this flaw to gain access to the private key information in the file.
Created attachment 1146471[details]
Proposed patch
I am amending the proposed patch to use the -Z flag on mv, and to credit jcline in the commit message for independently reporting the issue.