REDHAT-BUG-2492478: High severity Rclone Rclone vulnerability
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. The remote value is parsed from the URL and passed to normal backend initialization. Inline remote configuration can set backend options that execute local commands during initialization. As a result, a single unauthenticated GET or HEAD request can execute a command as the rclone process user. This vulnerability is fixed in 1.74.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rcloneto a version that resolves this vulnerability.Fixed in 1.74.3
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2492478?
The severity of REDHAT-BUG-2492478 is rated high with a score of 7.
What is the risk associated with REDHAT-BUG-2492478?
The risk associated with REDHAT-BUG-2492478 is classified as 33.
How do I fix REDHAT-BUG-2492478?
To fix REDHAT-BUG-2492478, update Rclone to a version later than 1.74.3.
What vulnerabilities does REDHAT-BUG-2492478 introduce?
REDHAT-BUG-2492478 allows unauthenticated GET and HEAD requests, potentially exposing sensitive data.
Which versions of Rclone are affected by REDHAT-BUG-2492478?
Rclone versions from 1.46.0 to 1.74.3 are affected by REDHAT-BUG-2492478.