Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in rclone - CVE-2020-28924
Published: November 19, 2020 / Updated: November 20, 2020
Vulnerability identifier: #VU48568
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-28924
CWE-ID: CWE-338
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an attacker to decrypt or brute-force passwords.
The vulnerability exists due to Rclone uses a weak random number generator for generating passwords with much less entropy than advertised. An attacker, who is able to obtain the password protected file can decrypt data.
Affected software
rclone
Arch Linux
Gentoo Linux
Fedora
rclone
Arch Linux
Gentoo Linux
Fedora
rclone
How to mitigate CVE-2020-28924
Install updates from vendor's website.
rclone - update to 1.53.3
rclone - addressed in versions 1.53.3-1.el8, 1.53.3-1.fc33
rclone - addressed in versions 1.53.3-1.el8, 1.53.3-1.fc33