Project

General

Profile

Actions

tickets #160958

closed

Publicly exposed rsync (provo-downloadcontent.opensuse.org)

Added by cybersecurity@suse.com about 1 month ago. Updated about 1 month ago.

Status:
Resolved
Priority:
Normal
Assignee:
-
Category:
Mirrors
Target version:
-
Start date:
2024-05-27
Due date:
% Done:

0%

Estimated time:

Description

Dear Heroes of Opensuse,

Recently, a security finding has been found in opensuse infra, details of
which are given below:

Security Finding:
RSYNC port (873) is found open without authentication controls.
IP : 91.193.113.71 Port: 873

Recommended action:
Default rsync port to be blocked and RSYNC to be used with SSH
authentication.

Best Regards,
Shiwang on behalf of SUSE Cybersecurity Team.


Related issues 1 (1 open0 closed)

Has duplicate openSUSE admin - tickets #160979: Re: Publicly exposed rsync (provo-downloadcontent.opensuse.org)Newbmwiedemann2024-05-27

Actions
Actions

Also available in: Atom PDF