#VU37002 Information disclosure in rclone - CVE-2018-12907 

 

#VU37002 Information disclosure in rclone - CVE-2018-12907

Published: June 27, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU37002
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-12907
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
rclone
Software vendor:
rclone.org

Description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of any URL's content to Google, because there is no validation of a URL field received from the Google Cloud Storage API server, aka a "RESTLESS" issue.


Remediation

Install update from vendor's website.

External links