Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-79781

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 6.5

Описание

rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys. Attackers can send requests with object keys like ../root-secret.txt to escape the bucket namespace and access files in the serve root directory.

A flaw was found in rclone. This path traversal vulnerability allows a remote attacker to read and overwrite sensitive files outside of their intended directory by manipulating S3 object keys with 'dot-dot' segments (e.g., ../). This could lead to unauthorized access and modification of critical system files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat/cryostat-storage-rhel9Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2523572github.com/rclone/rclone: rclone: Path Traversal allows unauthorized file access

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
23 дня назад

rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys. Attackers can send requests with object keys like ../root-secret.txt to escape the bucket namespace and access files in the serve root directory.

CVSS3: 6.5
nvd
23 дня назад

rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys. Attackers can send requests with object keys like ../root-secret.txt to escape the bucket namespace and access files in the serve root directory.

CVSS3: 6.5
debian
23 дня назад

rclone serve s3 before 1.74.4 contains a path traversal vulnerability ...

CVSS3: 6.5
github
23 дня назад

rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys. Attackers can send requests with object keys like ../root-secret.txt to escape the bucket namespace and access files in the serve root directory.

6.5 Medium

CVSS3