CVE-2019-15522: Linbit CSYNC2
Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.
An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in daemon.c neglects to force a failure of a hello command when the configuration requires use of SSL.
Affected products
- Linbit CSYNC2: up to and including 2.0
Published 2020-03-20. Last modified 2026-06-17.