It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.
CVSS Details
- CVSS 3.1 Base Score: 5.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ubuntu | — | Upgrade apportUpgrade python3-apportUpgrade python-apportUpgrade python-apport (Ubuntu Pro)Upgrade python3-apport (Ubuntu Pro)Upgrade apport (Ubuntu Pro) | May 26, 2021 | May 25, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub