Path Traversal Vulnerability in rsync Affects Red Hat
CVE-2024-12087
7.5HIGH
Key Information:
- Vendor
Samba
- Vendor
- CVE Published:
- 14 January 2025
What is CVE-2024-12087?
A path traversal vulnerability in rsync allows a malicious server to exploit the --inc-recursive
option, which is often enabled by default. This vulnerability arises from insufficient symlink verification and deduplication checks that occur on a per-file-list basis. An attacker could leverage this flaw to write files outside of the client's intended destination directory, potentially placing harmful files in arbitrary locations that mimic valid directories and paths on the client system.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Credit
Red Hat would like to thank Jasiel Spelman (Google), Pedro Gallegos (Google), and Simon Scannell (Google) for reporting this issue.