Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-52522

Опубликовано: 15 нояб. 2024
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2volsync-containerAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-281
Дефект:
CWE-59
Дефект:
CWE-61
https://bugzilla.redhat.com/show_bug.cgi?id=2326544rclone: librclone: improper permission and ownership handling on symlink targets with --links and --metadata

EPSS

Процентиль: 6%
0.00024
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

ubuntu
около 1 года назад

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.

nvd
около 1 года назад

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.

debian
около 1 года назад

Rclone is a command-line program to sync files and directories to and ...

CVSS3: 5.5
github
около 1 года назад

Rclone has Improper Permission and Ownership Handling on Symlink Targets with --links and --metadata

EPSS

Процентиль: 6%
0.00024
Низкий

6.8 Medium

CVSS3