#VU37002 Information disclosure in rclone - CVE-2018-12907
Published: June 27, 2018 / Updated: August 8, 2020
Vulnerability identifier: #VU37002
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-12907
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
rclone
rclone
Software vendor:
rclone.org
rclone.org
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of any URL's content to Google, because there is no validation of a URL field received from the Google Cloud Storage API server, aka a "RESTLESS" issue.
Remediation
Install update from vendor's website.