
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2018-21269 affects OpenRC through version 0.42.1. The vulnerability was discovered and disclosed on October 27, 2020. The issue exists in the checkpath functionality of OpenRC, which might allow local users to take ownership of arbitrary files because a non-terminal path component can be a symlink (NVD).
The vulnerability is classified as CWE-59 (Improper Link Resolution Before File Access) with a CVSS v3.1 Base Score of 5.5 MEDIUM (Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N) and CVSS v2.0 Base Score of 2.1 LOW (Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N) (NVD).
The vulnerability allows local users to take ownership of arbitrary files on the system by manipulating symlinks in non-terminal path components. This can lead to privilege escalation and unauthorized file ownership changes. For example, an attacker could potentially change the ownership of sensitive files like /etc/passwd (GitHub Issue).
The vulnerability can be exploited by local users who have the ability to create and manipulate symlinks in directories that are processed by OpenRC's checkpath functionality. A proof of concept exists demonstrating how an attacker can exploit the vulnerability by replacing a directory with a symlink to gain ownership of arbitrary files like /etc/passwd (GitHub Issue).
Users should upgrade OpenRC to a version newer than 0.42.1 which contains fixes for this vulnerability. Until an upgrade is possible, administrators should carefully review and restrict permissions on directories that are processed by OpenRC's checkpath functionality (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."