在 rclone 1.74.4 之前的版本中,当 S3 重定向将同一主机上的协议从 HTTPS 更改为 HTTP 时,未能移除 X-Amz-Security-Token 请求头。攻击者可以拦截明文 HTTP 流量,从而捕获在请求头中发送的 AWS STS 会话令牌。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-79781 | 6.5 MEDIUM | rclone serve s3 Path Traversal via dot-dot object keys |
| CVE-2026-79775 | 6.5 MEDIUM | rclone Archive Backend SquashFS Parser Denial of Service |
| CVE-2026-79780 | 5.3 MEDIUM | rclone before v1.75.0 Credential Exposure via S3 Redirect |
| CVE-2026-79779 | 5.3 MEDIUM | rclone before v1.75.0 WebDAV Credential Exposure via HTTPS-to-HTTP Redirect |
| CVE-2026-79778 | 5.3 MEDIUM | rclone before v1.75.0 Denial of Service via TUS nil-response panic |
| CVE-2026-79776 | 5.3 MEDIUM | rclone before 1.75.0 Authentication Bypass via pprof |
| CVE-2026-79783 | 3.6 LOW | rclone before 1.74.4 Privilege Escalation via setuid Metadata |
| CVE-2026-79777 | 2.7 LOW | rclone before v1.75.0 Information Disclosure via RC API |
No comments yet