CVE-2024-12088
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 14, 2025
CWE ID 35
Summary
CVE-2024-12088 is a newly identified cybersecurity vulnerability affecting the rsync utility. When the `--safe-links` option is enabled, rsync fails to adequately verify if symbolic link destinations harbor further symbolic links within them. This shortcoming leads to a path traversal issue, allowing unauthorized access and possible arbitrary file writing beyond the intended directory. This vulnerability poses a significant risk for data confidentiality and integrity, emphasizing the importance of promptly updating affected rsync installations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.