Bugzilla – Bug 1190045
VUL-0: CVE-2021-3755: rsync: command injection on the remote host when copying files
Last modified: 2024-05-13 18:12:19 UTC
rh#1999680 A command injection vulnerability was found in Rsync. An attacker can use this vulnerability to execute arbitrary commands on a remote host via arguments passed to Rsync for a copy operation. The attacker needs to know the SSH login password to be able to exploit this issue. References: https://bugzilla.redhat.com/show_bug.cgi?id=1999680 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-3755
@Pedro: there are not a lot of details, do you have any more insight what this is about by chance ?
Thanks for opening the bug. There is not much information yet about it and nothing related in upstream Github. From the bug description, I can see that to reproduce it the attacker needs to know the ssh key! I'll keep an eye upstream and in RH Bugzilla.