漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
Vulnerability Description
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user's private repository on backends that clean path components. This issue is fixed in version 1.74.4.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Rclone 路径遍历漏洞
Vulnerability Description
Rclone是Rclone团队开源的一款同步文件到各类云存储服务的命令行工具。 Rclone 1.74.4之前版本存在安全漏洞,该漏洞源于在对后端对象的URL路径进行处理时未清理路径组件,导致已认证用户可在请求中包含..从而读取、覆盖或删除其他用户的私有仓库。
CVSS Information
N/A
Vulnerability Type
N/A