PT-2026-71625 · Rsync · Rsync
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
rsync versions prior to 3.5.0
Description
Authenticated clients can bypass module-level filter restrictions by providing malicious
--filter merge file directives. During filter evaluation, attackers can inject client-side merge file directives to create rules that override the restrictions set by the daemon module, allowing unauthorized access to files that were intended to be excluded.Recommendations
Update rsync to version 3.5.0 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rsync