Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-70463

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing.

An authorization bypass flaw was found in the rsync daemon. The auth users directive parser incorrectly handles group names containing spaces due to comma-only tokenization. This flaw causes deny rules to be silently discarded, allowing an authenticated user to bypass restrictions and gain unauthorized access to restricted modules.

Отчет

This is an Important authorization bypass in rsync, affecting configurations that utilize the auth users directive with group names containing spaces. The flaw allows an authenticated, but unauthorized, user to access restricted rsync modules due to incorrect parsing of deny rules. This bypass occurs because the rsync parser fails to properly tokenize group names with embedded spaces, silently discarding intended access restrictions.

Меры по смягчению последствий

To prevent this authorization bypass, ensure that no group names containing spaces are used within the auth users directive in the rsyncd.conf configuration file. Review and update any existing configurations to remove spaces from group names in this directive. After making changes, restart the rsync service for the new configuration to take effect. For example, use systemctl restart rsyncd if managing the service with systemd. Note that restarting the service will temporarily interrupt active rsync operations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rsyncAffected
Red Hat Enterprise Linux 6rsyncNot affected
Red Hat Enterprise Linux 7rsyncAffected
Red Hat Enterprise Linux 8rsyncAffected
Red Hat Enterprise Linux 9rsyncAffected
Red Hat OpenShift Container Platform 4rhcosAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2515385rsync: rsync: Authorization bypass via `auth users` directive parsing

EPSS

Процентиль: 27%
0.00343
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
18 дней назад

rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing.

CVSS3: 8.1
nvd
18 дней назад

rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing.

CVSS3: 8.1
debian
18 дней назад

rsync 3.1.0 before 3.5.0contains an authorization bypass in auth users ...

suse-cvrf
11 дней назад

Security update for rsync

suse-cvrf
14 дней назад

Security update for rsync

EPSS

Процентиль: 27%
0.00343
Низкий

8.1 High

CVSS3