CVE-2018-12907

Source
https://cve.org/CVERecord?id=CVE-2018-12907
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-12907.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-12907
Published
2018-06-27T13:29:00.263Z
Modified
2026-07-08T14:59:35.392239Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of any URL's content to Google, because there is no validation of a URL field received from the Google Cloud Storage API server, aka a "RESTLESS" issue.

References

Affected packages

Git / github.com/rclone/rclone

Affected ranges

Type
GIT
Repo
https://github.com/rclone/rclone
Events
Database specific
{
    "cpe": "cpe:2.3:a:rclone:rclone:1.42:*:*:*:*:*:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "1.42"
        },
        {
            "last_affected": "1.42"
        }
    ]
}

Affected versions

1.*
1.42
v1.*
v1.42

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-12907.json"