Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-12088

28
FAUCET Score

CVE-2024-12088 is a path traversal vulnerability in rsync, specifically when using the --safe-links option. It affects various Linux distributions and products like AlmaLinux, Red Hat, and Samba. An attacker can exploit this flaw by sending a crafted symbolic link destination from the server, leading to arbitrary file writes outside the intended directory. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and high impact on integrity. While there is no known active exploitation (KEV) or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion and media coverage, suggesting awareness and potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.3.0CPE matchmatch criteria
cpe:2.3:a:samba:rsync:*:*:*:*:*:*:*:*
1.14CPE matchmatch criteria
cpe:2.3:a:redhat:discovery:1.14:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
4.65%
Probability of exploitation in next 30 days
EPSS Percentile
90.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0465 is in the 84th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

microsoftpatch availablevia msrc
Product: 17120-16823Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: 17490-17084Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: 19944-17086Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: 19946-17084Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: cbl2 rsync 3.4.1-1 on CBL Mariner 2.0Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: azl3 rsync 3.4.1-1 on Azure Linux 3.0Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: cbl2 rsync 3.2.5-1 on CBL Mariner 2.0Fixed in: 3.4.1-1
microsoftpatch availablevia msrc
Product: azl3 rsync 3.2.7-1 on Azure Linux 3.0Fixed in: 3.4.1-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: rsync-0:3.1.3-21.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: rsync-0:3.2.5-3.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 1.14Fixed in: discovery/discovery-ui-rhel9:sha256:c960fa13577db72b52765d6941688f431f61fe38adb717b2d8bb6569e241bc5e
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhcos
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: rsync

Vendor Advisories (2)

redhatCVE-2024-12088Moderate

rsync: --safe-links option bypass leads to path traversal

Jan 14, 2025
microsoft2025-Jan/CVE-2024-12088Moderate

Rsync: --safe-links option bypass leads to path traversal

Jan 14, 2025

References

github.com / google/security-research/security/advisories/GHSA-p5pg-x43v-mvqj
Third Party Advisory
lists.debian.org / debian-lts-announce/2025/01/msg00008.html
security.netapp.com / advisory/ntap-20250131-0002
kb.cert.org / vuls/id/952657
access.redhat.com / errata/RHBA-2025:6470
access.redhat.com / errata/RHSA-2025:2600
Third Party Advisory
access.redhat.com / errata/RHSA-2025:7050
Third Party Advisory
access.redhat.com / errata/RHSA-2025:8385
Third Party Advisory
access.redhat.com / security/cve/CVE-2024-12088
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
kb.cert.org / vuls/id/952657
Third Party Advisory