Логотип exploitDog
bind:CVE-2024-52522
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-52522

Количество 5

Количество 5

ubuntu логотип

CVE-2024-52522

около 1 года назад

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.

EPSS: Низкий
redhat логотип

CVE-2024-52522

около 1 года назад

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2024-52522

около 1 года назад

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.

EPSS: Низкий
debian логотип

CVE-2024-52522

около 1 года назад

Rclone is a command-line program to sync files and directories to and ...

EPSS: Низкий
github логотип

GHSA-hrxh-9w67-g4cv

около 1 года назад

Rclone has Improper Permission and Ownership Handling on Symlink Targets with --links and --metadata

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-52522

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.

0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-52522

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.

CVSS3: 6.8
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-52522

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.

0%
Низкий
около 1 года назад
debian логотип
CVE-2024-52522

Rclone is a command-line program to sync files and directories to and ...

0%
Низкий
около 1 года назад
github логотип
GHSA-hrxh-9w67-g4cv

Rclone has Improper Permission and Ownership Handling on Symlink Targets with --links and --metadata

CVSS3: 5.5
0%
Низкий
около 1 года назад

Уязвимостей на страницу