Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

ubuntu логотип

CVE-2026-70463

18 дней назад

rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2026-70463

18 дней назад

rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-70463

18 дней назад

rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2026-70463

18 дней назад

rsync 3.1.0 before 3.5.0contains an authorization bypass in auth users ...

CVSS3: 8.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3657-1

11 дней назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3634-1

14 дней назад

Security update for rsync

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21650-1

5 дней назад

Security update for rsync

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-70463

rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing.

CVSS3: 8.1
0%
Низкий
18 дней назад
redhat логотип
CVE-2026-70463

rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing.

CVSS3: 8.1
0%
Низкий
18 дней назад
nvd логотип
CVE-2026-70463

rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing.

CVSS3: 8.1
0%
Низкий
18 дней назад
debian логотип
CVE-2026-70463

rsync 3.1.0 before 3.5.0contains an authorization bypass in auth users ...

CVSS3: 8.1
0%
Низкий
18 дней назад
suse-cvrf логотип
SUSE-SU-2026:3657-1

Security update for rsync

11 дней назад
suse-cvrf логотип
SUSE-SU-2026:3634-1

Security update for rsync

14 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21650-1

Security update for rsync

5 дней назад

Уязвимостей на страницу