
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-32550 is a security vulnerability discovered in the read_file() function within apport/hookutils.py. The vulnerability was identified when this function is used by the openjdk-14 package apport hooks, where it would follow symbolic links or open FIFOs, potentially exposing private data to other local users (NVD, Ubuntu).
The vulnerability exists in the read_file() function of apport/hookutils.py, which would incorrectly follow symbolic links and open FIFOs without proper validation. The issue received a CVSS 3.1 Base Score of 5.5 (MEDIUM) from NIST with vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, while Canonical Ltd. assessed it with a Base Score of 7.3 (HIGH) with vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L (NVD).
When exploited, this vulnerability could allow local users to expose private data through the openjdk-14 package apport hooks. The vulnerability primarily affects the confidentiality of the system, with high impact potential for data exposure (Launchpad Bug).
The vulnerability requires local access and can be exploited when the read_file() function is used by the openjdk-14 package apport hooks. The exploitation involves creating symbolic links to sensitive files that could then be read through the vulnerable function (Launchpad Bug).
The vulnerability was patched by updating apport to prevent following symbolic links and ensuring the file isn't a FIFO in read_file(). The fix was implemented across multiple Ubuntu versions including 18.04 LTS, 20.04 LTS, 20.10, and 21.04. The patches were released on May 25, 2021 (Launchpad Bug).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."