CVE-2018-12907: Infoleak
Published Jun 27, 2018
·Updated
In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of any URL's content to Google, because there is no validation of a URL field received from the Google Cloud Storage API server, aka a "RESTLESS" issue.
Affected Software
1 affected component
Rclone Rclone=1.42
Event History
Jun 27, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12907?
CVE-2018-12907 has a severity rating of high, with a CVSS score of 7.5.
2
How do I fix CVE-2018-12907?
To fix CVE-2018-12907, upgrade Rclone to a version later than 1.42 which addresses this vulnerability.
3
What impact does CVE-2018-12907 have?
CVE-2018-12907 allows attackers to potentially transmit any URL's content to Google, leading to information leakage.
4
In which software is CVE-2018-12907 found?
CVE-2018-12907 is found in Rclone version 1.42.
5
What type of issue is CVE-2018-12907 classified as?
CVE-2018-12907 is classified as an information leak vulnerability.