7.4
CVSSv3

CVE-2022-29154

Published: 02/08/2022 Updated: 07/11/2023
CVSS v3 Base Score: 7.4 | Impact Score: 5.2 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

An issue exists in rsync prior to 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rsync client target directory and subdirectories (for example, overwrite the .ssh/authorized_keys file).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

samba rsync

fedoraproject fedora 35

fedoraproject fedora 36

Vendor Advisories

Debian Bug report logs - #1016543 rsync: CVE-2022-29154 Package: src:rsync; Maintainer for src:rsync is Paul Slootman <paul@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 2 Aug 2022 17:21:06 UTC Severity: important Tags: security, upstream Found in version rsync/324-1 Reply or ...
A flaw was found in rsync that is triggered by a victim rsync user/client connecting to a malicious rsync server The server can copy and overwrite arbitrary files in the client's rsync target directory and subdirectories This flaw allows a malicious server, or in some cases, another attacker who performs a man-in-the-middle attack, to potentially ...
A flaw was found in rsync that is triggered by a victim rsync user/client connecting to a malicious rsync server The server can copy and overwrite arbitrary files in the client's rsync target directory and subdirectories This flaw allows a malicious server, or in some cases, another attacker who performs a man-in-the-middle attack, to potentially ...
Synopsis Important: OpenShift Virtualization 487 Images bug fixes and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Virtualization release 487 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a secur ...
Synopsis Important: rsync security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rsync is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a secu ...
Synopsis Important: rsync security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rsync is now available for Red Hat Enterprise Linux 84 Extended Update SupportRed Hat Product Security has rated th ...
Synopsis Important: rsync security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rsync is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a secu ...
Synopsis Moderate: OpenShift Container Platform 4113 packages and security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4113 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Con ...
Synopsis Important: OpenShift Container Platform 41031 security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 41031 is now available withupdates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impact ...
Synopsis Important: rsync security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rsync is now available for Red Hat Enterprise Linux 81 Update Services for SAP SolutionsRed Hat Product Security ha ...
Synopsis Important: rsync security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rsync is now available for Red Hat Enterprise Linux 82 Extended Update SupportRed Hat Product Security has rated th ...
Synopsis Important: OpenShift Virtualization 496 Images security and bug fix update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Virtualization release 496 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a securit ...
Synopsis Important: OpenShift Container Platform 4948 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 4948 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Co ...
Synopsis Moderate: OpenShift Container Platform 4948 extras security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4948 is now available withupdates to packages and images that fix several bugsRed Hat Product Security has rated this update as having a security impact of Moderate A Co ...
Synopsis Important: OpenShift Container Platform 4661 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 4661 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Co ...
Synopsis Moderate: OpenShift Container Platform 4661 security and extras update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4661 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Conta ...
Synopsis Important: OpenShift Container Platform 4849 security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 4849 is now available withupdates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impactof ...
Synopsis Moderate: OpenShift Container Platform 4759 bug fix and security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4759 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Cont ...
Synopsis Moderate: Logging Subsystem 551 Security and Bug Fix Update Type/Severity Security Advisory: Moderate Topic Logging Subsystem 551 - Red Hat OpenShiftRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity ratin ...
Synopsis Important: Red Hat Virtualization security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for redhat-release-virtualization-host, redhat-virtualization-host, and redhat-virtualization-host-produ ...
Synopsis Critical: Red Hat Advanced Cluster Management 252 security fixes and bug fixes Type/Severity Security Advisory: Critical Topic Red Hat Advanced Cluster Management for Kubernetes 252 GeneralAvailability release images, which fix security issues and bugsRed Hat Product Security has rated this update as having a security impactof C ...
Synopsis Moderate: Openshift Logging Security and Bug Fix update (5311) Type/Severity Security Advisory: Moderate Topic Openshift Logging Bug Fix Release (5311)Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rat ...
Synopsis Moderate: Multicluster Engine for Kubernetes 21 security updates and bug fixes Type/Severity Security Advisory: Moderate Topic Multicluster Engine v21Red Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, ...
Synopsis Moderate: OpenShift API for Data Protection (OADP) 104 security and bug fix update Type/Severity Security Advisory: Moderate Topic OpenShift API for Data Protection (OADP) 104 is now availableRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base ...
概述 Moderate: Logging Subsystem 545 Security and Bug Fix Update 类型/严重性 Security Advisory: Moderate 标题 Logging Subsystem 545 - Red Hat OpenShiftRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rat ...
Synopsis Moderate: Red Hat Advanced Cluster Management 260 security updates and bug fixes Type/Severity Security Advisory: Moderate Topic Red Hat Advanced Cluster Management for Kubernetes 260 GeneralAvailability release images, which fix security issues and bugsRed Hat Product Security has rated this update as having a security impactof ...
Synopsis Moderate: Red Hat Advanced Cluster Management 2312 security updates and bug fixes Type/Severity Security Advisory: Moderate Topic Red Hat Advanced Cluster Management for Kubernetes 2312 GeneralAvailability release images, which provide security updates and bug fixesRed Hat Product Security has rated this update as having a secur ...
Synopsis Moderate: OpenShift API for Data Protection (OADP) 110 security and bug fix update Type/Severity Security Advisory: Moderate Topic OpenShift API for Data Protection (OADP) 110 is now availableRed Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerability Scoring System (CVSS) base s ...
Synopsis Critical: Multicluster Engine for Kubernetes 202 security and bug fixes Type/Severity Security Advisory: Critical Topic Multicluster Engine for Kubernetes 202 General Availability release images, which fix bugs and update container imagesRed Hat Product Security has rated this update as having a security impactof Critical A Com ...
Synopsis Moderate: OpenShift Container Platform 311784 security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 311784 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Container Pl ...
Synopsis Important: Migration Toolkit for Containers (MTC) 174 security and bug fix update Type/Severity Security Advisory: Important Topic The Migration Toolkit for Containers (MTC) 174 is now availableRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) ba ...
Synopsis Moderate: RHACS 372 enhancement and security update Type/Severity Security Advisory: Moderate Topic Updated images are now available for Red Hat Advanced Cluster Security for Kubernetes (RHACS) The updated image includes new features and bug fixesRed Hat Product Security has rated this update as having a security impact of Moderat ...
Synopsis Important: Red Hat OpenShift Data Foundation 4130 security and bug fix update Type/Severity Security Advisory: Important Topic Updated images that include numerous enhancements, security, and bug fixes are now available in Red Hat Container Registry for Red Hat OpenShift Data Foundation 4130 on Red Hat Enterprise Linux 9Red Hat ...
Synopsis Critical: Red Hat Advanced Cluster Management 246 security update and bug fixes Type/Severity Security Advisory: Critical Topic Red Hat Advanced Cluster Management for Kubernetes 246 GeneralAvailability release images, which fix bugs and update container imagesRed Hat Product Security has rated this update as having a security i ...
Synopsis Moderate: Openshift Logging Bug Fix Release and Security Update (5312) Type/Severity Security Advisory: Moderate Topic An update is now available for OpenShift Logging 5312Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which gives a ...
概要 Moderate: OpenShift sandboxed containers 131 security fix and bug fix update タイプ/重大度 Security Advisory: Moderate トピック OpenShift sandboxed containers 131 is now available 説明 OpenShift sandboxed containers support for OpenShift Container Platformprovides users with built-in support for running Kata containe ...
Synopsis Moderate: OpenShift Virtualization 4111 security and bug fix update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Virtualization release 4111 is now available with updates to packages and images that fix several bugs and add enhancementsRed Hat Product Security has rated this update as having a security impac ...
A flaw was found in rsync that is triggered by a victim rsync user/client connecting to a malicious rsync server The server can copy and overwrite arbitrary files in the client's rsync target directory and subdirectories This flaw allows a malicious server, or in some cases, another attacker who performs a man-in-the-middle attack, to potentially ...
An out-of-bounds access flaw was found in zlib, which allows memory corruption when deflating (ex: when compressing) if the input has many distant matches For some rare inputs with a large number of distant matches (crafted payloads), the buffer into which the compressed or deflated data is written can overwrite the distance symbol table which it ...

Github Repositories

HIP2022 presentation materials.

CVE-2022-29154 Authors: Ege BALCI, Taha HAMAD This repository contains the HIP2022 presentation materials for CVE-2022-29154 vulnerability The full presentation recording is available here but the slides in the video are added later (offline) by the conference team and it is an old version hence missing a lot of pages and the demo video :/ The PDF in this repo is the actual pr

simplified grype CLI

vuln-scanner Description This is a command line interface tool based on the @anchore's grype It scans SBOM file and reports the vulnerabilities found in the image This tool has its benefits over grype It is less resource intensive and has simple and easy to use interface Installation $ git clone $ cd vuln-scanner $ go build -o vuln-scanner