GHSA-xf75-659h-cgg5
uutils coreutils has a Link Following Issue
Details
A vulnerability in the tail utility of uutils coreutils allows for the exfiltration of sensitive file contents when using the --follow=name option. Unlike GNU tail, the uutils implementation continues to monitor a path after it has been replaced by a symbolic link, subsequently outputting the contents of the link's target. In environments where a privileged user (e.g., root) monitors a log directory, a local attacker with write access to that directory can replace a log file with a symlink to a sensitive system file (such as /etc/shadow), causing tail to disclose the contents of the sensitive file.
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for coreutils. Pin to a known-safe version or switch to an alternative.