The vendor explicitly identifies these products as affected by this CVE.
- cryostat/cryostat-storage-rhel9 as a component of Cryostat 4
- rhacm2/volsync-rhel9 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- Summary
- A flaw was found in rclone. In the WebDAV TUS creation handler, a vulnerability allows a malicious or compromised configured endpoint to trigger a denial of service. By resetting connections during TUS uploads, an attacker can cause the application to panic, terminating processes and halting unrelated work. This leads to a complete disruption of service.
- Remediation
- Avoid using rclone's WebDAV backend with TUS-enabled servers from untrusted sources. If TUS uploads are not required, use a WebDAV server configuration that does not advertise TUS support.
