Select your cookie preferences

We use cookies and similar tools to enhance your experience, provide our services, deliver relevant advertising, and make improvements. Approved third parties also use these tools to help us deliver advertising and provide certain site features.

CVE-2022-29154

Public on 2022-08-02
Modified on 2023-01-27
Description

A flaw was found in rsync that is triggered by a victim rsync user/client connecting to a malicious rsync server. The server can copy and overwrite arbitrary files in the client's rsync target directory and subdirectories. This flaw allows a malicious server, or in some cases, another attacker who performs a man-in-the-middle attack, to potentially overwrite sensitive files on the client machine, resulting in further exploitation.

Severity
Important
See what this means
CVSS v3 Base Score
7.4
See breakdown
Continue reading

Affected Packages

Platform Package Release Date Advisory
Amazon Linux 2 - Core rsync 2022-10-31 19:40 ALAS2-2022-1873
Amazon Linux 2023 rsync 2023-02-17 20:41 ALAS2023-2023-002

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.4 AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/
NVD CVSSv3 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H