Database/Control plane, storage & DevOps
rclone (rc server, /debug/pprof handler): The pprof debug handler is mounted as its own route on the rclone
Impact
The pprof debug handler is mounted as its own route on the rclone remote-control server, outside the fail-closed authentication check that guards everything else. An unauthenticated caller fetches /debug/pprof/cmdline and gets the full argv of the rclone process - which for a data mover means the object-storage access keys, bucket names and endpoints passed on the command line. The same gap also lets an unauthenticated caller enumerate the configured remote names.
Who can reach it
Anyone who can reach the rclone rc port. Data-staging jobs on GPU clusters routinely run rclone with --rc bound to the node interface so a controller can drive it, which puts this in reach of any co-tenant on the cluster network.
What to do
Upgrade rclone to the release carrying this fix and restart the rc server. Independently, stop passing credentials as command-line arguments - move them to the rclone config file or environment - and bind --rc-addr to localhost with --rc-user/--rc-pass set. No CVE ID has been assigned; track it by the GHSA.
References
Related entries
- Nagios XI: systemd unit files shipped with unnecessary executable permissionsCVE-2025-34135 · Nagios XI (nagios.service systemd unit file permissions)Medium
- Keycloak: OIDC authentication flaw - attacker reusing data from a same-realm request impersonates a userCVE-2023-0264 · KeycloakMedium
- MySQL Server: InnoDB flaw allowing a high-privileged network attacker to cause a repeatable DoSCVE-2022-21417 · MySQL ServerMedium
- MySQL Server: InnoDB flaw - a high-privileged network attacker can hang or repeatedly crash the serverCVE-2023-22084 · MySQL ServerMedium
- RabbitMQ: HTTP API enforces no request body limitCVE-2023-46118 · RabbitMQMedium
- Elasticsearch: elasticsearch-certutil --csr writes the private key to disk unencrypted despite --passCVE-2024-23444 · ElasticsearchMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.