CVE-2018-12907: Infoleak

Published Jun 27, 2018
·
Updated

In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of any URL's content to Google, because there is no validation of a URL field received from the Google Cloud Storage API server, aka a "RESTLESS" issue.

Affected Software

1 affected component
Rclone Rclone=1.42

Event History

Jun 27, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2018-12907?

CVE-2018-12907 has a severity rating of high, with a CVSS score of 7.5.

2

How do I fix CVE-2018-12907?

To fix CVE-2018-12907, upgrade Rclone to a version later than 1.42 which addresses this vulnerability.

3

What impact does CVE-2018-12907 have?

CVE-2018-12907 allows attackers to potentially transmit any URL's content to Google, leading to information leakage.

4

In which software is CVE-2018-12907 found?

CVE-2018-12907 is found in Rclone version 1.42.

5

What type of issue is CVE-2018-12907 classified as?

CVE-2018-12907 is classified as an information leak vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203