CVE-2018-12907

    Dashboard / Vulnerabilities / CVE-2018-12907

    CVE-2018-12907

    Published: 27 Jun 2018Last Modified: 8 Jul 2026

    Summary:

    Details: In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of any URL's content to Google, because there is no validation of a URL field received from the Google Cloud Storage API server, aka a "RESTLESS" issue.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- a9adb4389628c086c0183c8daa1c8a59004f08b6
    Fixed -None

    Affected versions

    1.42

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High