Information disclosure in rclone - CVE-2018-12907

 

Information disclosure in rclone - CVE-2018-12907

Published: June 27, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU37002
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12907
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of any URL's content to Google, because there is no validation of a URL field received from the Google Cloud Storage API server, aka a "RESTLESS" issue.


Affected software

rclone

How to mitigate CVE-2018-12907

Install update from vendor's website.


External References

Related Security Bulletins