Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-70454

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt or tamper with rsync session content without detection by the client.

A flaw was found in the rsync-ssl wrapper script's TLS certificate validation. An on-path attacker can present self-signed or invalid certificates to intercept, decrypt, or tamper with encrypted sessions. Because rsync fails to validate the certificate against a trusted CA or verify hostname matching, this interception occurs without detection by the client.

Отчет

This Moderate impact flaw in rsync allows on-path attackers to intercept and tamper with encrypted sessions. The vulnerability arises from insufficient TLS certificate validation, enabling an attacker to present invalid certificates and compromise data integrity and confidentiality without detection. Exploitation requires an attacker to be positioned to intercept network traffic between the rsync client and server.

Меры по смягчению последствий

Do not use rsync-ssl with the openssl or stunnel backends. Use rsync over SSH, which authenticates the host and encrypts the session: rsync -avz -e ssh /source user@remote:/destination. If daemon TLS cannot be avoided, restrict those sessions to trusted networks

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rsyncAffected
Red Hat Enterprise Linux 6rsyncNot affected
Red Hat Enterprise Linux 7rsyncNot affected
Red Hat Enterprise Linux 8rsyncNot affected
Red Hat Enterprise Linux 9rsyncAffected
Red Hat OpenShift Container Platform 4rhcosAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2515373rsync: rsync: TLS Certificate Validation Bypass allows interception of encrypted sessions

EPSS

Процентиль: 9%
0.0019
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 8
ubuntu
18 дней назад

rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt or tamper with rsync session content without detection by the client.

CVSS3: 8
nvd
18 дней назад

rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt or tamper with rsync session content without detection by the client.

msrc
8 дней назад

rsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode

CVSS3: 8
debian
18 дней назад

rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 ( ...

suse-cvrf
11 дней назад

Security update for rsync

EPSS

Процентиль: 9%
0.0019
Низкий

6.8 Medium

CVSS3