In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of any URL's content to Google, because there is no validation of a URL field received from the Google Cloud Storage API server, aka a "RESTLESS" issue.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://openwall.com/lists/oss-security/2018/06/27/3 | third party advisory mailing list |
https://www.danieldent.com/blog/restless-vulnerability-non-browser-cross-domain-http-request-attacks/ | mitigation third party advisory |