PT-2026-81371 · Rclone · Rclone
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
rclone versions prior to 1.74.4
Description
The software fails to strip the
X-Amz-Security-Token header when an S3 redirect changes the scheme from HTTPS to HTTP on the same host. This allows attackers to intercept plaintext HTTP traffic and capture AWS Security Token Service (STS) session tokens sent in request headers.Recommendations
Update rclone to version 1.74.4 or later.
Exploit
Fix
Insufficiently Protected Credentials
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rclone