OSV 1.4.0 · unreviewed · 修改于 2026-08-26 02:31
发布时间
2026-08-26 02:31
GitHub 审查时间
—
NVD 发布时间
2026-08-26 00:17
源文件
advisories/unreviewed/2026/08/GHSA-98fh-ch8q-6529/GHSA-98fh-ch8q-6529.json
rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys. Attackers can send requests with object keys like ../root-secret.txt to escape the bucket namespace and access files in the serve root directory.
该公告没有提供结构化的受影响软件包信息。