Vulnerability Description
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.
Related Weaknesses (CWE)
References
- https://github.com/rclone/rclone/commit/01ccf204f42b4f68541b16843292439090a2dcf0
- https://github.com/rclone/rclone/security/advisories/GHSA-hrxh-9w67-g4cv
FAQ
What is CVE-2024-52522?
CVE-2024-52522 is a documented vulnerability. Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local...
How severe is CVE-2024-52522?
CVSS scoring is not yet available for CVE-2024-52522. Check NVD for updates.
Is there a patch for CVE-2024-52522?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.