Bug ID 1099926
Summary VUL-0: CVE-2018-12907: rclone: improper URL validation while migrating data between two storage buckets
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.3
Hardware Other
URL https://smash.suse.de/issue/209052/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Other
Assignee asarai@suse.com
Reporter meissner@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

rh#1597411

In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud
Storage buckets might allow attackers to trigger the transmission of any URL's
content to Google, because there is no validation of a URL field received from
the Google Cloud Storage API server, aka a "RESTLESS" issue.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1597411
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-12907
http://openwall.com/lists/oss-security/2018/06/27/3
https://www.danieldent.com/blog/restless-vulnerability-non-browser-cross-domain-http-request-attacks/


You are receiving this mail because: