Vulnerability Name: | CVE-2022-29154 (CCN-232637) | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2022-08-02 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Published: | 2022-08-02 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2022-10-27 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Summary: | An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories (for example, overwrite the .ssh/authorized_keys file). | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.4 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H) 6.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
6.4 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:C/A:N)
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-862 CWE-22 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-29154 Source: MLIST Type: Exploit, Mailing List, Patch, Third Party Advisory [oss-security] 20220802 CVE-2022-29154: Rsync client-side arbitrary file write vulnerability. Source: XF Type: UNKNOWN rsync-cve202229154-sec-bypass(232637) Source: CCN Type: rsync GIT Repository rsync Source: MISC Type: Release Notes, Third Party Advisory https://github.com/WayneD/rsync/tags Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2022-15da0cf165 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2022-25e4dbedf9 Source: CCN Type: oss-sec Mailing List, Tue, 2 Aug 2022 11:53:25 +0300 CVE-2022-29154: Rsync client-side arbitrary file write vulnerability. Source: CCN Type: IBM Security Bulletin 6831591 (Robotic Process Automation) Multiple Security Vulnerabilities may affect IBM Robotic Process Automation for Cloud Pak Source: CCN Type: IBM Security Bulletin 6838295 (QRadar Network Packet Capture) IBM QRadar Network Packet Capture includes components with multiple known vulnerabilities. Source: CCN Type: IBM Security Bulletin 6857803 (Cloud Pak for Watson AIOps) Multiple Vulnerabilities in CloudPak for Watson AIOPs Source: CCN Type: IBM Security Bulletin 6955057 (Security QRadar SIEM) IBM QRadar SIEM includes multiple components with known vulnerabilities Source: CCN Type: IBM Security Bulletin 6980521 (Security Verify Access) IBM Security Verify Access Appliance includes components with known vulnerabilities (CVE-2022-29154, CVE-2022-0391) Source: CCN Type: IBM Security Bulletin 6999317 (Security Guardium) IBM Security Guardium is affected by multiple vulnerabilities Source: CCN Type: IBM Security Bulletin 7001867 (Cloud Pak for Security) IBM Cloud Pak for Security includes components with multiple known vulnerabilities Source: CCN Type: Mend Vulnerability Database CVE-2022-29154 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration RedHat 7: Configuration RedHat 8: Configuration RedHat 9: Configuration RedHat 10: Configuration RedHat 11: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
BACK |