Related Vulnerabilities: CVE-2022-29154  

A flaw was found in rsync that is triggered by a victim rsync user/client connecting to a malicious rsync server. The server can copy and overwrite arbitrary files in the client's rsync target directory and subdirectories. This flaw allows a malicious server, or in some cases, another attacker who performs a man-in-the-middle attack, to potentially overwrite sensitive files on the client machine, resulting in further exploitation.

Description

A flaw was found in rsync that is triggered by a victim rsync user/client connecting to a malicious rsync server. The server can copy and overwrite arbitrary files in the client's rsync target directory and subdirectories. This flaw allows a malicious server, or in some cases, another attacker who performs a man-in-the-middle attack, to potentially overwrite sensitive files on the client machine, resulting in further exploitation.

Mitigation

Only connecting to trusted Rsync servers over trusted channels would help to mitigate this flaw.

Additional Information

  • Bugzilla 2110928: CVE-2022-29154 rsync: remote arbitrary files write inside the directories of connecting peers
  • FAQ: Frequently asked questions about CVE-2022-29154