/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2024-52522

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-52522

Severity

Unknown

Summary

Rclone Improper Permission and Ownership Handling on Symlink Targets with --links and --metadata

Description

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing