mlocate's %post script allows RUNUPDATEDBAS user to make arbitrary files world readable by abusing insecure file operations that run with root privileges.
{ "urgency": "not yet assigned" }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-32190.json"