Database/Control plane, storage & DevOps
rclone (S3 backend, redirect sanitization): When rclone's S3 backend follows a redirect it strips some sensitive
Impact
When rclone's S3 backend follows a redirect it strips some sensitive headers but not IBM IAM bearer tokens or SSE-C customer-supplied encryption keys. An attacker who can steer a redirect harvests the bearer token, and the SSE-C key is the thing standing between them and the plaintext of the encrypted objects - so this leaks both the credential and the key material for a dataset store in one shot.
Who can reach it
An attacker positioned to influence the HTTP redirect chain between rclone and the object store - a hostile or compromised endpoint, or a network position on the cluster's egress path.
What to do
Upgrade rclone to the fixed release. Rotate any IBM IAM credentials and SSE-C keys that were used with a redirecting endpoint. Pin the S3 endpoint and disable redirect following where your object store does not need it. No CVE ID has been assigned; track it by the GHSA.
References
Related entries
- SPI flash descriptor region configuration on a wide range of Supermicro boards: Any software running with sufficientCVE-2018-13787 · SPI flash descriptor region configuration on a wide range of Supermicro boardsMedium
- HPE ProLiant Gen10 System ROM (security restriction bypass): A local bypass of security restrictions in the System ROMCVE-2021-29213 · HPE ProLiant Gen10 System ROM (security restriction bypass)Medium
- Intel oneAPI Data Analytics Library (oneDAL): An uncontrolled library search path: the component loads a shared libraryCVE-2022-25905 · Intel oneAPI Data Analytics Library (oneDAL)Medium
- Intel MPI Library (oneAPI HPC Toolkit): An uncontrolled library search path: the component loads a shared libraryCVE-2022-26052 · Intel MPI Library (oneAPI HPC Toolkit)Medium
- Intel oneAPI Deep Neural Network Library (oneDNN): An uncontrolled library search path: the component loads a sharedCVE-2022-26076 · Intel oneAPI Deep Neural Network Library (oneDNN)Medium
- Intel oneAPI OpenMP runtime: An uncontrolled library search path: the component loads a shared library by nameCVE-2022-26345 · Intel oneAPI OpenMP runtimeMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.