CVE-2024-12087
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-12087 is a newly disclosed path traversal vulnerability affecting the rsync utility. This issue arises when the `--inc-recursive` option, a default setting for many clients and servers, is used. This option enables the transfer of symbolic links and recursively processes subdirectories. The vulnerability lies in the lack of proper symlink verification and deduplication checks that occur on a per-file basis. Consequently, a malicious server can manipulate the symbolic links and write malicious files outside of the intended client destination directory, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.