Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

github логотип

GHSA-4j4q-473w-9q2r

3 месяца назад

Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2026-43617

3 месяца назад

Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2026-43617

3 месяца назад

Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2026-43617

3 месяца назад

Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.

CVSS3: 4.8
EPSS: Низкий
msrc логотип

CVE-2026-43617

3 месяца назад

Rsync < 3.4.3 Authorization Bypass via Hostname Resolution

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2026-43617

3 месяца назад

Rsync version3.4.2 and prior contain an authorization bypass vulnerabi ...

CVSS3: 4.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20877-1

2 месяца назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2083-1

2 месяца назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2048-1

2 месяца назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2038-1

3 месяца назад

Security update for rsync

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4j4q-473w-9q2r

Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.

CVSS3: 4.8
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-43617

Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.

CVSS3: 4.8
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-43617

Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.

CVSS3: 4.2
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-43617

Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access control list enforcement when configured with chroot. Attackers can bypass hostname-based deny rules by controlling the PTR record for their source IP address, allowing connections from hostnames that administrators intended to deny when reverse DNS resolution fails and defaults to UNKNOWN.

CVSS3: 4.8
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-43617

Rsync < 3.4.3 Authorization Bypass via Hostname Resolution

CVSS3: 4.8
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-43617

Rsync version3.4.2 and prior contain an authorization bypass vulnerabi ...

CVSS3: 4.8
0%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20877-1

Security update for rsync

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2083-1

Security update for rsync

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2048-1

Security update for rsync

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2038-1

Security update for rsync

3 месяца назад

Уязвимостей на страницу