{"id":"CVE-2021-32553","details":"It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 package apport hooks, it could expose private data to other local users.","modified":"2026-07-08T07:11:39.393547423Z","published":"2021-06-12T04:15:12.157Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:20.10:*:*:*:*:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:21.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:21.10:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"18.04"},{"last_affected":"18.04"},{"introduced":"20.04"},{"last_affected":"20.04"},{"introduced":"20.10"},{"last_affected":"20.10"},{"introduced":"21.04"},{"last_affected":"21.04"},{"introduced":"21.10"},{"last_affected":"21.10"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux"}]},"references":[{"type":"REPORT","url":"https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1917904"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openjdk/jdk","events":[{"introduced":"dfacda488bfbe2e11e8d607a6d08527710286982"},{"last_affected":"dfacda488bfbe2e11e8d607a6d08527710286982"}],"database_specific":{"cpe":"cpe:2.3:a:oracle:openjdk:17:*:*:*:*:*:*:*","extracted_events":[{"introduced":"17"},{"last_affected":"17"}],"source":"CPE_STRING"}}],"versions":["17","jdk-17-ga","jdk-17+35"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32553.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}