Описание
rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.
A flaw was found in rclone. Attackers can exploit this vulnerability by triggering panics in the RC API error responses. This can lead to the disclosure of sensitive internal information, such as file paths, module versions, goroutine states, and memory addresses, potentially aiding further attacks.
Отчет
A flaw was found in rclone. The Remote Control (RC) API can include sensitive information such as internal paths, configuration details, or error context in error responses. An authenticated administrator with access to the RC API can observe this information, which may aid in further attacks against the system.
Меры по смягчению последствий
Restrict access to the rclone RC API to trusted networks and administrators only. Use the --rc-allow-origin and --rc-user/--rc-pass flags to enforce authentication. Where possible, disable the RC API entirely if not required for operations.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Cryostat 4 | cryostat/cryostat-storage-rhel9 | Fix deferred | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/volsync-rhel9 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
2.7 Low
CVSS3
Связанные уязвимости
rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.
rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.
rclone before v1.75.0 includes full Go stack traces in RC API error re ...
rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.
2.7 Low
CVSS3