CVE-2024-52522 - CVE House
Back to Database
Status published Medium CVE-2024-52522

Rclone Improper Permission and Ownership Handling on Symlink Targets with --links and --metadata

Vulnerability Description

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-52522

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

rclone
Vulnerable Versions:
>= 1.59.0, < 1.68.2

Timeline

Official Publish: November 15th, 2024
Last Modified: November 21st, 2024
Added to House: July 22nd, 2026

CVSS Vectors