A flaw was found in rsync in versions since 3.2.0pre1. Rsync improperly validates certificate with host mismatch vulnerability. A remote, unauthenticated attacker could exploit the flaw by performing a man-in-the-middle attack using a valid certificate for another hostname which could compromise confidentiality and integrity of data transmitted using rsync-ssl. The highest threat from this vulnerability is to data confidentiality and integrity. This flaw affects rsync versions before 3.2.4.
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade rsync | Aug 22, 2024 | May 27, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 27, 2021 |
| Debian | — | Upgrade rsync | Jul 30, 2024 | May 27, 2021 |
| Dell Powerstore Dsa2024225 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | May 29, 2024 |
| Dell Powerstore Dsa2024287 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jul 2, 2024 |
| Dell Powerstore Dsa2024336 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Aug 1, 2024 |
| Gentoo Linux | — | Upgrade net-misc/rsync. | May 10, 2024 | May 27, 2021 |
| Oracle Solaris | — | Upgrade network/rsync to version 3.2.3-11.4.35.0.1.94.3 on Solaris 11.4 | Jul 21, 2021 | May 27, 2021 |
| Suse | — | Upgrade rsync | Aug 9, 2024 | May 27, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | May 27, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub