CVE
CVE-2022-29154
CVE ID |
CVE-2022-29154
|
---|---|
CVSS Score |
7.4
|
Operating System | |
Affected Versions |
CentOS 8
|
Patched Versions |
3.1.3-12_ol001.el8
|
Patch Date |
|
Additional Information
NVD Listing: https://nvd.nist.gov/vuln/detail/CVE-2022-29154
An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories (for example, overwrite the .ssh/authorized_keys file).