CVE-2024-52522
Severity CVSS v4.0:
MEDIUM
Type:
CWE-59
Link Following
Publication date:
15/11/2024
Last modified:
21/11/2024
Description
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.
Impact
Base Score 4.0
5.40
Severity 4.0
MEDIUM
Base Score 3.x
5.50
Severity 3.x
MEDIUM



