PT-2026-81369 · Rclone · Rclone
CVSS v4.0
6.0
Medium
| Vector | AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
rclone versions prior to 1.75.0
Description
The software fails to sanitize IBM IAM bearer tokens and SSE-C (Server-Side Encryption with Customer-Provided Keys) encryption keys during S3 redirect callbacks. This allows credentials to be preserved when there are changes to the scheme or host. An attacker monitoring network traffic from a trusted endpoint can capture reusable IBM IAM tokens during same-host HTTPS-to-HTTP downgrades or capture SSE-C keys during cross-origin redirects to gain unauthorized access to protected S3 objects.
Recommendations
Update rclone to version 1.75.0 or later.
Exploit
Fix
Insufficiently Protected Credentials
Cleartext Transmission of Sensitive Information
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rclone