The vendor explicitly identifies these products as affected by this CVE.
- cryostat/cryostat-storage-rhel9 as a component of Cryostat 4
- rhacm2/volsync-rhel9 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
- Summary
- A flaw was found in rclone. The application fails to properly sanitize IBM IAM bearer tokens and Server-Side Encryption with Customer-Provided Keys (SSE-C) encryption keys during S3 redirect callbacks. This allows credentials to be preserved across scheme or host changes. A remote attacker observing network traffic from a trusted endpoint could capture reusable IBM IAM tokens on same-host HTTPS-to-HTTP downgrades or SSE-C keys on cross-origin redirects, leading to information disclosure and potential unauthorized access to protected S3 objects.
- Remediation
- Fix deferred
