Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract can write extracted files outside the user-select…
中危 CVSS 5.0
摘要
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract can write extracted files outside the user-selected destination prefix when extracting a crafted archive containing parent path components such as ../, allowing creation or overwrite of sibling objects in the same bucket or path scope. This issue is fixed in version 1.74.4.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/rclone/rclone/commit/1a746732441e8158f32fab35924b23701e719a8c Patch
- https://github.com/rclone/rclone/commit/d11efe0d58fe6a2d6d90675bb9d8ee5840c51e1d Patch
- https://github.com/rclone/rclone/releases/tag/v1.74.4 Release Notes
- https://github.com/rclone/rclone/security/advisories/GHSA-4vr5-p2gc-h23p Exploit
时间线
- nvd_ingest NVD