CVE-2024-52522

MEDIUM5.5EPSS 0.03%

Rclone Improper Permission and Ownership Handling on Symlink Targets with --links and --metadata in github.com/rclone/rclone

Published: 11/19/2024Modified: 2/4/2026
Also known as:GHSA-hrxh-9w67-g4cvBIT-rclone-2024-52522CGA-8h7w-gq43-qr33GO-2024-3271

Description

Rclone Improper Permission and Ownership Handling on Symlink Targets with --links and --metadata in github.com/rclone/rclone

Affected packages (4)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
osvCVSS 3.1MEDIUM5.5CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

References (5)