Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
Vulnerability Description
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleaned URL path, allowing an authenticated user to include .. in a request such as //..//config and read, overwrite, or delete another user's private repository on backends that clean path components. This issue is fixed in version 1.74.4.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Rclone 路径遍历漏洞
Vulnerability Description
Rclone是Rclone团队开源的一款同步文件到各类云存储服务的命令行工具。 Rclone 1.74.4之前版本存在安全漏洞,该漏洞源于在对后端对象的URL路径进行处理时未清理路径组件,导致已认证用户可在请求中包含..从而读取、覆盖或删除其他用户的私有仓库。
CVSS Information
N/A
Vulnerability Type
N/A