Sploitus

CVE-2024-52522

No indexed exploits for CVE-2024-52522 yet

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.

Affected products
Alt Linux, Debian, Rclone
Fix
Available
CVSS 4.0
5.4 MEDIUM
EPSS
0.2% (12th percentile)
Weakness
CWE-281, CWE-61, CWE-59
NVD status
Deferred
Published
2024-11-15
CVE-2024-52522 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-52522 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-52522 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.