{"id":"AZL-55676","summary":"CVE-2024-12088 affecting package rsync for versions less than 3.4.1-1","details":"A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.","modified":"2026-04-01T05:19:43.570523Z","published":"2025-01-14T18:15:25Z","upstream":["CVE-2024-12088"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12088"}],"affected":[{"package":{"name":"rsync","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/rsync"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-55676.json"}}],"schema_version":"1.7.5"}