MEDIUM✓ PATCH🇬🇧 English

CVE-2024-12086

CVSS 6.1v3.1pub. 2025-01-14upd. 2026-06-30

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to determine what data needs to be sent to the server. By sending specially constructed checksum values for arbitrary files, an attacker may be able to reconstruct the data of those files byte-by-byte based on the responses from the client.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
  • Almalinux

    OS
    Almalinux
    10.08.09.0
  • Archlinux Arch Linux

    OS
    Archlinux
    wszystkie wersje
  • Gentoo Linux

    OS
    Gentoo
    wszystkie wersje
  • Nixos

    OS
    Nixos
    < 24.11
  • Red Hat Enterprise Linux

    OS
    Redhat
    10.06.07.08.09.0
  • Red Hat OpenShift Container Platform

    APP
    Redhat
    4.0
  • Samba Rsync

    APP
    Samba
    ≤ 3.3.0
  • SUSE Linux

    OS
    Suse
    wszystkie wersje
  • Tritondatacenter Smartos

    OS
    Tritondatacenter
    < 20250123
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Referencje

Powiązane podatności

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓ten sam produkt

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓ten sam produkt

SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego

CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓ten sam produkt

RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu

CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓ten sam produkt

Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE

CVE-2019-1003030CRITICAL9.9⚠ KEVPL ✓ten sam produkt

Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)