Back to Database
Status published
Medium
CVE-2022-48682
In deletefiles in FDUPES before 2.2.0, a TOCTOU race condition...
Vulnerability Description
In deletefiles in FDUPES before 2.2.0, a TOCTOU race condition allows arbitrary file deletion via a symlink.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-48682
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/adrianlopezroche/fdupes/blob/4b6bcde1b3eb1cebe87cd30814f7d6cf4ee46e95/fdupes.c
- https://github.com/adrianlopezroche/fdupes/commit/85680897148f1ac33b55418e00334116e419717f
- https://bugzilla.suse.com/show_bug.cgi?id=1200381
- https://github.com/adrianlopezroche/fdupes/compare/v2.1.2...v2.2.0
More from n/a
View All →CVE-2025-9910
Versions of the package jsondiffpatch before 0.7.2 are vulnerable to...
Low
2.3
CVE-2025-9802
RemoteClinic profile.php sql injection
Medium
5.1
CVE-2025-9799
Langfuse Webhook promptRouter.ts promptChangeEventSourcing server-side request forgery
Low
2.3
CVE-2025-9775
RemoteClinic edit-my-profile.php unrestricted upload
Medium
6.9
CVE-2025-9774
RemoteClinic edit-patient.php information disclosure
Medium
5.3
Affected Vendor
Affected Software
Unknown
Vulnerable Versions:
Unknown
Timeline
Official Publish:
April 26th, 2024
Last Modified:
October 27th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AC:H/AV:L/A:H/C:N/I:H/PR:L/S:U/UI:R
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.