Database/Control plane, storage & DevOps
rclone (rc API, operations/fsinfo): operations/fsinfo is reachable without authentication and accepts an
Impact
operations/fsinfo is reachable without authentication and accepts an attacker-defined backend, so a caller can point it at a WebDAV remote whose bearer_token_command runs a shell command. Same practical outcome as the rcd RCE: code execution on the data-mover host and access to every credential in its config.
Who can reach it
Any host that can reach the rclone rc HTTP endpoint.
What to do
Upgrade rclone and restart all rc/serve instances. Rotate the credentials in the rclone config for anything the host could reach. Enforce authentication on the rc endpoint and keep it off shared networks.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.