Canonical Ubuntu Pro Client Insecure Symlink Vulnerability in Log Collection Command
Vulnerability
A vulnerability allowing insecure symlink following has been identified in Canonical Ubuntu Pro Client (formerly Ubuntu Advantage Tools) within the 'pro collect-logs' command framework. This issue arises because the utility creates or uses predictable temporary file paths or user-accessible log directories for gathering diagnostic information, without verifying the file type or ownership. An unprivileged local attacker can exploit this by creating a symbolic link at a predictable destination that points to an arbitrary, root-readable file, such as '/etc/shadow' or private files in '/root'. When a root administrator executes the 'pro collect-logs' command, the tool follows the symlink, reads the target file, and compresses its contents into a diagnostic support archive. Since the output archive is accessible to the unprivileged user, the attacker can extract and read the sensitive root-owned files, resulting in complete information disclosure of system secrets.
Impact
Exploitation of this vulnerability leads to unauthorized access to sensitive root-owned files, such as those containing password hashes or private information, allowing for a complete disclosure of system secrets.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
