Impact
rclone versions before 1.75.0 do not sanitize IBM IAM bearer tokens and SSE-C encryption keys when handling S3 redirect callbacks, which can preserve those secrets across scheme changes or host modifications. This flaw can expose authenticating tokens that grant access to protected S3 objects.
Affected Systems
The vulnerability affects all rclone rclone releases prior to 1.75.0 that use IBM Cloud Object Storage with redirect callbacks. Users employing S3 redirect features with IBM IAM tokens or SSE-C keys are at risk.
Risk and Exploitability
The flaw carries a CVSS score of 6.0, indicating a moderate impact. With an EPSS score of 0.00095 (less than 1%), the lack of an entry in the CISA KEV catalog suggests limited documented exploitation. An attacker who can observe traffic from a trusted endpoint—for example, during same-host HTTPS-to-HTTP downgrades or cross-origin redirect flows—can capture reusable IBM IAM tokens or SSE-C keys, gaining unauthorized access to S3 data. The primary attack vector is network eavesdropping during redirect callbacks.
OpenCVE Enrichment