VYPR

Bitnami package

rclone

pkg:bitnami/rclone

Vulnerabilities (8)

  • CVE-2026-59733HigJul 14, 2026
    affected < 1.74.4fixed 1.74.4

    Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw uncleane

  • CVE-2026-59732MedJul 14, 2026
    affected < 1.74.4fixed 1.74.4

    Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract can write extracted files outside the user-selected destination prefix when extracting a crafted archive containing parent path co

  • CVE-2026-54572HigJul 14, 2026
    affected < 1.74.4fixed 1.74.4

    Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target, allowing

  • CVE-2026-49980CriJun 24, 2026
    affected >= 1.46.0, < 1.74.3fixed 1.74.3

    Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.0 until 1.74.3, rclone rcd --rc-serve accepts unauthenticated GET and HEAD requests to paths of the form: /[remote:path]/object. The remote value is parsed from

  • CVE-2026-41179CriApr 23, 2026
    affected >= 1.48.0, < 1.73.5fixed 1.73.5

    Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to version 1.73.5, the RC endpoint `operations/fsinfo` is exposed without `AuthRequired: true` and accepts attacker-controlled `fs` i

  • CVE-2026-41176CriApr 23, 2026
    affected >= 1.45.0, < 1.73.5fixed 1.73.5

    Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, including the RC option block itself. Starting in v

  • CVE-2024-52522MedNov 15, 2024
    affected >= 1.59.0, < 1.68.2fixed 1.68.2

    Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions o

  • CVE-2020-28924HigNov 19, 2020
    affected < 1.53.3fixed 1.53.3

    An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy than advertised. The suggested passwords depend deterministically on the time the second rclone was s