PT-2026-71640 · Rsync · Rsync
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
rsync versions prior to 3.5.0
Description
An arbitrary file read issue exists due to improper symlink following during the handling of input configuration files. Attackers can read files accessible to the rsync daemon process by placing a symlink at a predictable path for
--files-from or --password-file, or by providing a --files-from path that escapes the daemon module root. This affects the processing of --files-from, --password-file, and filter merge files.Recommendations
Update rsync to version 3.5.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rsync