Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vqwj-943v-724g

Опубликовано: 25 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2
CVSS3: 3.6

Описание

rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservation from an untrusted remote, attackers can plant a setuid binary that escalates privileges to root if rclone runs as root, or to the service account user otherwise.

rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservation from an untrusted remote, attackers can plant a setuid binary that escalates privileges to root if rclone runs as root, or to the service account user otherwise.

EPSS

Процентиль: 4%
0.0014
Низкий

2 Low

CVSS4

3.6 Low

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 3.6
ubuntu
23 дня назад

rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservation from an untrusted remote, attackers can plant a setuid binary that escalates privileges to root if rclone runs as root, or to the service account user otherwise.

CVSS3: 3.6
redhat
23 дня назад

rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservation from an untrusted remote, attackers can plant a setuid binary that escalates privileges to root if rclone runs as root, or to the service account user otherwise.

CVSS3: 3.6
nvd
23 дня назад

rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservation from an untrusted remote, attackers can plant a setuid binary that escalates privileges to root if rclone runs as root, or to the service account user otherwise.

CVSS3: 3.6
debian
23 дня назад

rclone before 1.74.4 fails to mask special permission bits when applyi ...

EPSS

Процентиль: 4%
0.0014
Низкий

2 Low

CVSS4

3.6 Low

CVSS3

Дефекты

CWE-732