rclone kayıtları
rclone üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %92,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-306 Missing Authentication for Critical Function2
- CWE-190 Integer Overflow or Wraparound1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2026-49980İstismar yok | Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fixrclone · rclone · CWE-306 | Kritik9,8 | — | %0,8 | 24 Haz 2026 |
39İzleyin | CVE-2026-88018İstismar yok | rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypassrclone · rclone · CWE-287 | Kritik9,8 | — | %0,8 | 10 Eyl 2026 |
38İzleyin | CVE-2026-41179Kavram kanıtı | RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command executionrclone · rclone · CWE-78 | Kritik9,2 | — | %5,3 | 22 Nis 2026 |
37İzleyin | CVE-2026-41176Kavram kanıtı | Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command executionrclone · rclone · CWE-306 | Kritik9,2 | — | %3,2 | 22 Nis 2026 |
35İzleyin | CVE-2026-59733İstismar yok | rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositoriesrclone · rclone · CWE-22 | Yüksek8,8 | — | %0,6 | 14 Tem 2026 |
35İzleyin | CVE-2026-54572İstismar yok | rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remoterclone · rclone · CWE-59 | Yüksek8,8 | — | %0,4 | 14 Tem 2026 |
30İzleyin | CVE-2020-28924İstismar yok | An issue was discovered in Rclone before 1.53.3.rclone · rclone · CWE-331 | Yüksek7,5 | — | %1,4 | 19 Kas 2020 |
30İzleyin | CVE-2018-12907İstismar yok | In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmissrclone · rclone · CWE-200 | Yüksek7,5 | — | %1,3 | 27 Haz 2018 |
29İzleyin | CVE-2026-88017İstismar yok | rclone: FTP cross-session auth-proxy backend confusionrclone · rclone · CWE-488 | Yüksek7,3 | — | %0,4 | 10 Eyl 2026 |
28İzleyin | CVE-2026-88016İstismar yok | rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destinationrclone · rclone · CWE-59 | Yüksek7,1 | — | %0,3 | 10 Eyl 2026 |
25İzleyin | CVE-2026-88014İstismar yok | rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespacerclone · rclone · CWE-22 | Orta6,3 | — | %0,2 | 10 Eyl 2026 |
21İzleyin | CVE-2026-88015İstismar yok | rclone local: crafted Range request against a translated symlink panics (DoS)rclone · rclone · CWE-190 | Orta5,3 | — | %0,5 | 10 Eyl 2026 |
21İzleyin | CVE-2026-88013İstismar yok | rclone: http backend forwards custom/auth headers to a different host on redirectrclone · rclone · CWE-200 | Orta5,3 | — | %0,2 | 10 Eyl 2026 |
20İzleyin | CVE-2026-59732İstismar yok | rclone archive extract allows S3 destination prefix escape via crafted archive pathsrclone · rclone · CWE-22 | Orta5,0 | — | %0,2 | 14 Tem 2026 |
- CVE-2026-4998039İzleyin
Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix
KritikCVSS 9,8İstismar yokEPSS %1rclone · rclone24 Haz 2026
- CVE-2026-8801839İzleyin
rclone serve s3: --auth-proxy without --auth-key authenticates nobody - full SigV4 signature bypass
KritikCVSS 9,8İstismar yokEPSS %1rclone · rclone10 Eyl 2026
- CVE-2026-4117938İzleyin
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
KritikCVSS 9,2Kavram kanıtıEPSS %5rclone · rclone22 Nis 2026
- CVE-2026-4117637İzleyin
Rclone: Unauthenticated options/set allows runtime auth bypass, leading to sensitive operations and command execution
KritikCVSS 9,2Kavram kanıtıEPSS %3rclone · rclone22 Nis 2026
- CVE-2026-5973335İzleyin
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories
YüksekCVSS 8,8İstismar yokEPSS %1rclone · rclone14 Tem 2026
- CVE-2026-5457235İzleyin
rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote
YüksekCVSS 8,8İstismar yokEPSS %0rclone · rclone14 Tem 2026
- CVE-2020-2892430İzleyin
An issue was discovered in Rclone before 1.53.3.
YüksekCVSS 7,5İstismar yokEPSS %1rclone · rclone19 Kas 2020
- CVE-2018-1290730İzleyin
In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmiss
YüksekCVSS 7,5İstismar yokEPSS %1rclone · rclone27 Haz 2018
- CVE-2026-8801729İzleyin
rclone: FTP cross-session auth-proxy backend confusion
YüksekCVSS 7,3İstismar yokEPSS %0rclone · rclone10 Eyl 2026
- CVE-2026-8801628İzleyin
rclone: Directory metadata (chmod/chown/chtimes) applied through a planted symlink in rclone local --links escapes the destination
YüksekCVSS 7,1İstismar yokEPSS %0rclone · rclone10 Eyl 2026
- CVE-2026-8801425İzleyin
rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
OrtaCVSS 6,3İstismar yokEPSS %0rclone · rclone10 Eyl 2026
- CVE-2026-8801521İzleyin
rclone local: crafted Range request against a translated symlink panics (DoS)
OrtaCVSS 5,3İstismar yokEPSS %1rclone · rclone10 Eyl 2026
- CVE-2026-8801321İzleyin
rclone: http backend forwards custom/auth headers to a different host on redirect
OrtaCVSS 5,3İstismar yokEPSS %0rclone · rclone10 Eyl 2026
- CVE-2026-5973220İzleyin
rclone archive extract allows S3 destination prefix escape via crafted archive paths
OrtaCVSS 5,0İstismar yokEPSS %0rclone · rclone14 Tem 2026