Описание
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user's private repository on backends that clean path components. This issue is fixed in version 1.74.4.
A flaw was found in Rclone. When using the rclone serve restic --private-repos command, an authenticated user can include directory traversal sequences (e.g., ..) in a request. This allows them to bypass authorization and read, overwrite, or delete another user's private repository on backends that clean path components. This vulnerability can lead to significant information disclosure, data integrity issues, and denial of service for other users' data.
Отчет
This Moderate flaw in Rclone's serve restic --private-repos command allows an authenticated attacker to bypass authorization. By using directory traversal sequences in requests, an attacker can access, modify, or delete other users' private repositories. This could lead to unauthorized data access and integrity issues for users of affected Rclone services.
Меры по смягчению последствий
To mitigate this issue, avoid using the rclone serve restic --private-repos command if its functionality is not strictly required.
Upgrading to v1.74.4 fixes the issue.
Ссылки на источники
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user's private repository on backends that clean path components. This issue is fixed in version 1.74.4.
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user's private repository on backends that clean path components. This issue is fixed in version 1.74.4.
Rclone is a command-line program to sync files and directories to and ...
7.5 High
CVSS3