CVE-2024-12086
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Jan 14, 2025
CWE ID 390
Summary
CVE-2024-12086 is a newly discovered vulnerability in the rsync file transfer protocol. It allows a server to gain information about arbitrary files on a client's machine during data transfer. The issue arises when the rsync server sends checksum values of local data to the client for comparison. An attacker can manipulate these checksums to force the client to reveal the contents of targeted files, byte by byte, through the response messages. This vulnerability poses a significant risk for unauthorized data access and should be addressed promptly.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.