PT-2026-81368 · Rclone · Rclone
CVSS v4.0
6.0
Medium
| Vector | AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
rclone versions prior to 1.75.0
Description
The software fails to reject transport downgrades during redirect handling. This allows Basic authorization and Cookie headers to be replayed over plaintext HTTP following same-host HTTPS-to-HTTP redirects. An on-path attacker observing the plaintext communication can capture and reuse these credentials to perform WebDAV operations using the permissions of the compromised account.
Recommendations
Update rclone to version 1.75.0 or later.
Exploit
Fix
Insufficiently Protected Credentials
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rclone