Логотип exploitDog
bind:"CVE-2024-12087" OR bind:"CVE-2024-12088" OR bind:"CVE-2024-12747"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-12087" OR bind:"CVE-2024-12088" OR bind:"CVE-2024-12747"

Количество 31

Количество 31

ubuntu логотип

CVE-2024-12088

10 месяцев назад

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2024-12088

10 месяцев назад

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-12088

10 месяцев назад

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2024-12088

10 месяцев назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-12088

10 месяцев назад

A flaw was found in rsync. When using the `--safe-links` option, the r ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1330-1

7 месяцев назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0991-1

8 месяцев назад

Security update for rsync

EPSS: Низкий
github логотип

GHSA-gp7r-m4cc-qhwq

10 месяцев назад

A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-ffph-g3pc-8r3g

10 месяцев назад

A flaw was found in rsync. When using the `--safe-links` option, rsync fails to properly verify if a symbolic link destination contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2025-00373

12 месяцев назад

Уязвимость конфигурации -safe-links демона rsyncd утилиты для передачи и синхронизации файлов Rsync, позволяющая нарушителю записывать произвольные файлы

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2025-00372

11 месяцев назад

Уязвимость утилиты для передачи и синхронизации файлов Rsync, связанная с ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю повысить свои привилегии

CVSS3: 5.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-12088

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.

CVSS3: 6.5
2%
Низкий
10 месяцев назад
redhat логотип
CVE-2024-12088

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.

CVSS3: 6.5
2%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-12088

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.

CVSS3: 6.5
2%
Низкий
10 месяцев назад
msrc логотип
CVSS3: 7.5
2%
Низкий
10 месяцев назад
debian логотип
CVE-2024-12088

A flaw was found in rsync. When using the `--safe-links` option, the r ...

CVSS3: 6.5
2%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:1330-1

Security update for rsync

2%
Низкий
7 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0991-1

Security update for rsync

0%
Низкий
8 месяцев назад
github логотип
GHSA-gp7r-m4cc-qhwq

A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at the right time, it was possible to bypass the default behavior and traverse symbolic links. Depending on the privileges of the rsync process, an attacker could leak sensitive information, potentially leading to privilege escalation.

CVSS3: 5.6
0%
Низкий
10 месяцев назад
github логотип
GHSA-ffph-g3pc-8r3g

A flaw was found in rsync. When using the `--safe-links` option, rsync fails to properly verify if a symbolic link destination contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.

CVSS3: 6.5
2%
Низкий
10 месяцев назад
fstec логотип
BDU:2025-00373

Уязвимость конфигурации -safe-links демона rsyncd утилиты для передачи и синхронизации файлов Rsync, позволяющая нарушителю записывать произвольные файлы

CVSS3: 6.5
2%
Низкий
12 месяцев назад
fstec логотип
BDU:2025-00372

Уязвимость утилиты для передачи и синхронизации файлов Rsync, связанная с ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю повысить свои привилегии

CVSS3: 5.6
0%
Низкий
11 месяцев назад

Уязвимостей на страницу