CVE-2017-1000420

HIGH7.5EPSS 0.27%

Syncthing vulnerable to symlink traversal and arbitrary file overwrite

Published: 5/14/2022Modified: 11/8/2023
Also known as:GHSA-28xp-g7f6-7mhfDEBIAN-CVE-2017-1000420

Description

Syncthing version 0.14.33 and older erronously versions symlinks when they are deleted. If a directory is then created with the same name, a file created in that directory, and the file deleted, it is moved into the symlink target. This can lead to symlink traversal resulting in arbitrary file overwrite.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References (5)