HomeSambaCVE-2022-29154

CVE-2022-29154

HIGH
7.4CVSS
Published: 2022-08-02
Updated: 2024-11-21
AI Analysis

Description

An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories (for example, overwrite the .ssh/authorized_keys file).

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Vector
network
Complexity
high
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
none
Integrity
high
Availability
high
Weaknesses
CWE-20

Metadata

Primary Vendor
SAMBA
Published
8/2/2022
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

samba : rsyncfedoraproject : fedorafedoraproject : fedora

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2022-29154 | HIGH Severity | CVEDatabase.com | CVEDatabase.com