THREAT OPS › Threat News › [GHSA] GHSA-gx4c-2hqx-cw2r (low) — rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
[GHSA] GHSA-gx4c-2hqx-cw2r (low) — rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
GHSA-gx4c-2hqx-cw2r Severity: low CVE: None
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
## Vulnerability Details
**File**: `backend/s3/s3.go` **Lines**: 1359-1380 (functions `s3CheckRedirect` / `s3RedirectCrossesHost`)
### Root Cause Commit `e7b1eb774` (released in v1.74.3) added a `CheckRedirect` policy for the S3 HTTP client whose purpose is to
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- https://`url
- http://`url
- https://bucket.example.com`url
- http://bucket.example.com`url
Original source: https://github.com/advisories/GHSA-gx4c-2hqx-cw2r