CVE-2024-12088 is a path traversal vulnerability in rsync, specifically when using the --safe-links option. It affects various Linux distributions and products like AlmaLinux, Red Hat, and Samba. An attacker can exploit this flaw by sending a crafted symbolic link destination from the server, leading to arbitrary file writes outside the intended directory. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and high impact on integrity. While there is no known active exploitation (KEV) or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion and media coverage, suggesting awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.3.0CPE matchmatch criteria | cpe:2.3:a:samba:rsync:*:*:*:*:*:*:*:* | ||
1.14CPE matchmatch criteria | cpe:2.3:a:redhat:discovery:1.14:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.