Vulnerability record · CVE-2018-12907 · published 27 June 2018
CVE-2018-12907: Rclone information exposure vulnerability
Rclone · Rclone
In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of any URL's content to Google, because there is no validation of a URL field received from the Google Cloud Storage API server, aka a "RESTLESS" issue.
Description
In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of any URL's content to Google, because there is no validation of a URL field received from the Google Cloud Storage API server, aka a "RESTLESS" issue.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://openwall.com/lists/oss-security/2018/06/27/3 | Mailing ListThird Party Advisory |
| https://www.danieldent.com/blog/restless-vulnerability-non-browser-cross-domain-http-request-attacks/ | MitigationThird Party Advisory |
| http://openwall.com/lists/oss-security/2018/06/27/3 | Mailing ListThird Party Advisory |
| https://www.danieldent.com/blog/restless-vulnerability-non-browser-cross-domain-http-request-attacks/ | MitigationThird Party Advisory |
Track CVE-2018-12907 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-12907), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.