The vendor explicitly identifies these products as affected by this CVE.
- cryostat/cryostat-storage-rhel9 as a component of Cryostat 4
- rhacm2/volsync-rhel9 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- Summary
- A flaw was found in rclone. The application fails to reject transport downgrades during redirect handling, which allows Basic authorization and Cookie headers to be replayed over plaintext HTTP following HTTPS-to-HTTP redirects on the same host. An on-path attacker can observe this plaintext communication, capture, and reuse credentials, leading to unauthorized WebDAV operations with the compromised account's permissions.
- Remediation
- Fix deferred
