{
  "document": {
    "aggregate_severity": {
      "text": "Low"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos-stream8els/vex/2026/cve-2026-45232-els_os-centos-stream8els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-05-27T18:26:08Z",
      "generator": {
        "date": "2026-05-27T18:26:08Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-45232-ELS_OS-CENTOS-STREAM8ELS",
      "initial_release_date": "2026-05-20T02:16:00Z",
      "revision_history": [
        {
          "date": "2026-05-20T02:16:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-05-27T14:34:58Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-05-27T18:26:08Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-45232"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 8",
                "product": {
                  "name": "Community Enterprise Operating System 8",
                  "product_id": "CentOS-Stream-8",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:8:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-19.el8.1.x86_64",
                "product": {
                  "name": "rsync-0:3.1.3-19.el8.1.x86_64",
                  "product_id": "rsync-0:3.1.3-19.el8.1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/rsync@3.1.3-19.el8.1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-daemon-0:3.1.3-19.el8.1.noarch",
                "product": {
                  "name": "rsync-daemon-0:3.1.3-19.el8.1.noarch",
                  "product_id": "rsync-daemon-0:3.1.3-19.el8.1.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/rsync-daemon@3.1.3-19.el8.1?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els2.x86_64",
                "product": {
                  "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els2.x86_64",
                  "product_id": "rsync-0:3.1.3-19.el8.1.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.3-19.el8.1.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els5.x86_64",
                "product": {
                  "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els5.x86_64",
                  "product_id": "rsync-0:3.1.3-19.el8.1.tuxcare.els5.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.3-19.el8.1.tuxcare.els5?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els8.x86_64",
                "product": {
                  "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els8.x86_64",
                  "product_id": "rsync-0:3.1.3-19.el8.1.tuxcare.els8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.3-19.el8.1.tuxcare.els8?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els1.x86_64",
                "product": {
                  "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els1.x86_64",
                  "product_id": "rsync-0:3.1.3-19.el8.1.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.3-19.el8.1.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els6.x86_64",
                "product": {
                  "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els6.x86_64",
                  "product_id": "rsync-0:3.1.3-19.el8.1.tuxcare.els6.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.3-19.el8.1.tuxcare.els6?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els4.x86_64",
                "product": {
                  "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els4.x86_64",
                  "product_id": "rsync-0:3.1.3-19.el8.1.tuxcare.els4.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.3-19.el8.1.tuxcare.els4?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els7.x86_64",
                "product": {
                  "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els7.x86_64",
                  "product_id": "rsync-0:3.1.3-19.el8.1.tuxcare.els7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync@3.1.3-19.el8.1.tuxcare.els7?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els7.noarch",
                "product": {
                  "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els7.noarch",
                  "product_id": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els7.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync-daemon@3.1.3-19.el8.1.tuxcare.els7?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els5.noarch",
                "product": {
                  "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els5.noarch",
                  "product_id": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els5.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync-daemon@3.1.3-19.el8.1.tuxcare.els5?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els6.noarch",
                "product": {
                  "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els6.noarch",
                  "product_id": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els6.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync-daemon@3.1.3-19.el8.1.tuxcare.els6?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els8.noarch",
                "product": {
                  "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els8.noarch",
                  "product_id": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els8.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync-daemon@3.1.3-19.el8.1.tuxcare.els8?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els1.noarch",
                "product": {
                  "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els1.noarch",
                  "product_id": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els1.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync-daemon@3.1.3-19.el8.1.tuxcare.els1?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els4.noarch",
                "product": {
                  "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els4.noarch",
                  "product_id": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els4.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync-daemon@3.1.3-19.el8.1.tuxcare.els4?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els2.noarch",
                "product": {
                  "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els2.noarch",
                  "product_id": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els2.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/rsync-daemon@3.1.3-19.el8.1.tuxcare.els2?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els2.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els2.x86_64"
        },
        "product_reference": "rsync-0:3.1.3-19.el8.1.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els5.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els5.x86_64"
        },
        "product_reference": "rsync-0:3.1.3-19.el8.1.tuxcare.els5.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els8.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els8.x86_64"
        },
        "product_reference": "rsync-0:3.1.3-19.el8.1.tuxcare.els8.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els1.x86_64"
        },
        "product_reference": "rsync-0:3.1.3-19.el8.1.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els6.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els6.x86_64"
        },
        "product_reference": "rsync-0:3.1.3-19.el8.1.tuxcare.els6.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els4.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els4.x86_64"
        },
        "product_reference": "rsync-0:3.1.3-19.el8.1.tuxcare.els4.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-19.el8.1.tuxcare.els7.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els7.x86_64"
        },
        "product_reference": "rsync-0:3.1.3-19.el8.1.tuxcare.els7.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els7.noarch as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els7.noarch"
        },
        "product_reference": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els7.noarch",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els5.noarch as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els5.noarch"
        },
        "product_reference": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els5.noarch",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els6.noarch as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els6.noarch"
        },
        "product_reference": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els6.noarch",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els8.noarch as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els8.noarch"
        },
        "product_reference": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els8.noarch",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els1.noarch as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els1.noarch"
        },
        "product_reference": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els1.noarch",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els4.noarch as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els4.noarch"
        },
        "product_reference": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els4.noarch",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els2.noarch as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els2.noarch"
        },
        "product_reference": "rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els2.noarch",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-0:3.1.3-19.el8.1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.x86_64"
        },
        "product_reference": "rsync-0:3.1.3-19.el8.1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rsync-daemon-0:3.1.3-19.el8.1.noarch as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.noarch"
        },
        "product_reference": "rsync-daemon-0:3.1.3-19.el8.1.noarch",
        "relates_to_product_reference": "CentOS-Stream-8"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-45232",
      "cwe": {
        "id": "CWE-193",
        "name": "Off-by-one Error"
      },
      "notes": [
        {
          "category": "description",
          "text": "Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by positioning themselves between the client and proxy or controlling the proxy server to send a response line of 1023 or more bytes without a newline terminator, causing a null byte to be written to an out-of-bounds stack address when the RSYNC_PROXY environment variable is set.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els1.x86_64",
          "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els2.x86_64",
          "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els4.x86_64",
          "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els5.x86_64",
          "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els6.x86_64",
          "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els7.x86_64",
          "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els8.x86_64",
          "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.x86_64",
          "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.noarch",
          "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els1.noarch",
          "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els2.noarch",
          "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els4.noarch",
          "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els5.noarch",
          "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els6.noarch",
          "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els7.noarch",
          "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els8.noarch"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-45232"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/releases/tag/v3.4.3",
          "url": "https://github.com/RsyncProject/rsync/releases/tag/v3.4.3"
        },
        {
          "category": "external",
          "summary": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-8f85-j2cv-59m8",
          "url": "https://github.com/RsyncProject/rsync/security/advisories/GHSA-8f85-j2cv-59m8"
        },
        {
          "category": "external",
          "summary": "https://www.vulncheck.com/advisories/rsync-off-by-one-stack-write-via-http-proxy",
          "url": "https://www.vulncheck.com/advisories/rsync-off-by-one-stack-write-via-http-proxy"
        }
      ],
      "release_date": "2026-05-20T02:16:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-05-27T18:03:11.012921Z",
          "details": "- Exploitation requires a very specific, non-default setup: the rsync client must be configured to use an HTTP CONNECT proxy via the RSYNC_PROXY environment variable, and the attacker must control or intercept that proxy to return an oversized, unterminated line—making real-world exploitation in managed enterprise networks high‑complexity and narrow in scope. \n- The flaw is an off‑by‑one write of a single NUL byte on the stack, which is far more likely to crash the rsync client process than to enable code execution given modern mitigations (e.g., stack canaries, ASLR), yielding availability-only impact. \n- There is no confidentiality or integrity impact, and non‑proxy rsync usage and rsync daemons are unaffected, so this is a reasonable candidate for deprioritization.",
          "product_ids": [
            "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els1.x86_64",
            "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els2.x86_64",
            "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els4.x86_64",
            "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els5.x86_64",
            "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els6.x86_64",
            "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els7.x86_64",
            "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els8.x86_64",
            "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.x86_64",
            "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.noarch",
            "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els1.noarch",
            "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els2.noarch",
            "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els4.noarch",
            "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els5.noarch",
            "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els6.noarch",
            "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els7.noarch",
            "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els8.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els1.x86_64",
            "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els2.x86_64",
            "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els4.x86_64",
            "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els5.x86_64",
            "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els6.x86_64",
            "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els7.x86_64",
            "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.tuxcare.els8.x86_64",
            "CentOS-Stream-8:rsync-0:3.1.3-19.el8.1.x86_64",
            "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.noarch",
            "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els1.noarch",
            "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els2.noarch",
            "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els4.noarch",
            "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els5.noarch",
            "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els6.noarch",
            "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els7.noarch",
            "CentOS-Stream-8:rsync-daemon-0:3.1.3-19.el8.1.tuxcare.els8.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ]
    }
  ]
}