Описание
rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the daemon skips the rule rather than defaulting to a deny decision, enabling attackers who can trigger DNS failures to bypass module-level IP access controls and gain unauthorized access to restricted module file trees.
A flaw was found in rsync. This vulnerability allows a remote attacker to bypass hostname-based access control rules. By inducing DNS resolution failures, the rsync daemon incorrectly skips deny rules, granting unauthorized access to restricted module file trees.
Отчет
This Important flaw in rsync allows remote attackers to bypass hostname-based access controls. By inducing DNS resolution failures, an attacker can circumvent hosts deny rules, potentially gaining unauthorized access to restricted rsync module file trees on systems configured with hostname-based access controls and exposed to untrusted networks.
Меры по смягчению последствий
To mitigate this issue, configure rsync to use IP-based access controls instead of hostname-based rules in rsyncd.conf. Alternatively, restrict network access to the rsync daemon using firewall rules to allow connections only from trusted IP addresses or networks. This limits exposure by preventing untrusted remote attackers from reaching the service and attempting to induce DNS resolution failures. If changes are made to rsyncd.conf, the rsync daemon may need to be restarted or reloaded for the changes to take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | rsync | Affected | ||
| Red Hat Enterprise Linux 6 | rsync | Not affected | ||
| Red Hat Enterprise Linux 7 | rsync | Affected | ||
| Red Hat Enterprise Linux 8 | rsync | Affected | ||
| Red Hat Enterprise Linux 9 | rsync | Affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.4 High
CVSS3
Связанные уязвимости
rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the daemon skips the rule rather than defaulting to a deny decision, enabling attackers who can trigger DNS failures to bypass module-level IP access controls and gain unauthorized access to restricted module file trees.
rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the daemon skips the rule rather than defaulting to a deny decision, enabling attackers who can trigger DNS failures to bypass module-level IP access controls and gain unauthorized access to restricted module file trees.
rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure
rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerabili ...
EPSS
7.4 High
CVSS3