Описание
rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt or tamper with rsync session content without detection by the client.
A flaw was found in the rsync-ssl wrapper script's TLS certificate validation. An on-path attacker can present self-signed or invalid certificates to intercept, decrypt, or tamper with encrypted sessions. Because rsync fails to validate the certificate against a trusted CA or verify hostname matching, this interception occurs without detection by the client.
Отчет
This Moderate impact flaw in rsync allows on-path attackers to intercept and tamper with encrypted sessions. The vulnerability arises from insufficient TLS certificate validation, enabling an attacker to present invalid certificates and compromise data integrity and confidentiality without detection. Exploitation requires an attacker to be positioned to intercept network traffic between the rsync client and server.
Меры по смягчению последствий
Do not use rsync-ssl with the openssl or stunnel backends. Use rsync over SSH, which authenticates the host and encrypts the session: rsync -avz -e ssh /source user@remote:/destination. If daemon TLS cannot be avoided, restrict those sessions to trusted networks
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | rsync | Affected | ||
| Red Hat Enterprise Linux 6 | rsync | Not affected | ||
| Red Hat Enterprise Linux 7 | rsync | Not affected | ||
| Red Hat Enterprise Linux 8 | rsync | Not affected | ||
| Red Hat Enterprise Linux 9 | rsync | Affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.8 Medium
CVSS3
Связанные уязвимости
rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt or tamper with rsync session content without detection by the client.
rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt or tamper with rsync session content without detection by the client.
rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 ( ...
EPSS
6.8 Medium
CVSS3