Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects …
高危 CVSS 7.5
摘要
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target, allowing an attacker-controlled remote to plant an escaping symlink and cause a following object write to land outside the destination with attacker-chosen contents. This issue is fixed in version 1.74.4.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/rclone/rclone/commit/1154afebee986180b489084d38e2a0c578751498 Patch
- https://github.com/rclone/rclone/commit/874a804f5289517defdd7de68b2a374837080265 Patch
- https://github.com/rclone/rclone/releases/tag/v1.74.4 Release Notes
- https://github.com/rclone/rclone/security/advisories/GHSA-cf44-9pgv-m4xc Exploit
- https://github.com/rclone/rclone/security/advisories/GHSA-cf44-9pgv-m4xc Exploit
时间线
- nvd_ingest NVD