CVE-2024-52522
CVSS V2 None
CVSS V3 None
Description
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.
Overview
- CVE ID
- CVE-2024-52522
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-11-15T17:15:43.357Z
- Last Modified Date
- 2024-11-15T18:26:00.849Z
References
Reference URL | Reference Tags |
---|---|
https://github.com/rclone/rclone/security/advisories/GHSA-hrxh-9w67-g4cv | x_refsource_CONFIRM |
https://github.com/rclone/rclone/commit/01ccf204f42b4f68541b16843292439090a2dcf0 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-52522 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52522 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-11-16 13:44:26 | Added to TrackCVE |