CVE-2024-52522

Name
CVE-2024-52522
Description
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://github.com/rclone/rclone/security/advisories/GHSA-hrxh-9w67-g4cv
MISC https://github.com/rclone/rclone/commit/01ccf204f42b4f68541b16843292439090a2dcf0

Match rules

CPE URI Source package Min version Max version
rclone >= 1.59.0 < 1.68.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
rclone edge-community 1.68.2-r0 Mike Crute <mike@crute.us> fixed
rclone 3.20-community 1.66.0-r5 Mike Crute <mike@crute.us> possibly vulnerable