Impact
A time‑of‑check to time‑of‑use race condition exists in the rrsync restricted shell wrapper of rsync versions prior to 3.5.0. The flaw permits an authenticated client to substitute a symlink for a validated path component after the server has performed its directory checks but before the file transfer begins. This enables the client to escape the intended directory restrictions and gain access to files outside the designated subtree. Compounded by the ability for attackers to specify flags such as --copy-unsafe-links, -D, and --log-file, the vulnerability allows reading or writing sensitive files that should be protected.
Affected Systems
The affected product is rsync from the RsyncProject. All installations running rsync versions earlier than 3.5.0 are vulnerable; the fix is included in release 3.5.0 and later.
Risk and Exploitability
The CVSS score of 8.6 classifies this issue as a high‑severity vulnerability. Although the EPSS score is not available, the lack of a KEV listing suggests current exploitation is not widespread. The likely attack vector is a networked rsync session where the attacker is already authenticated to the target, and who can supply rrsync options. Successful exploitation gives the attacker confidentiality and integrity impact by reading or modifying arbitrary files within or outside the configured directory subtree, potentially escalating local privileges if the target account has sufficient permissions.
OpenCVE Enrichment