Actions
tickets #160958
closedPublicly exposed rsync (provo-downloadcontent.opensuse.org)
Status:
Resolved
Priority:
Normal
Assignee:
-
Category:
Mirrors
Target version:
-
Start date:
2024-05-27
Due date:
% Done:
0%
Estimated time:
Description
Dear Heroes of Opensuse,
Recently, a security finding has been found in opensuse infra, details of
which are given below:
Security Finding:
RSYNC port (873) is found open without authentication controls.
IP : 91.193.113.71 Port: 873
Recommended action:
Default rsync port to be blocked and RSYNC to be used with SSH
authentication.
Best Regards,
Shiwang on behalf of SUSE Cybersecurity Team.
Actions