THREAT OPS › Threat News › [GHSA] GHSA-h4mf-4v27-hggj (medium) — rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
[GHSA] GHSA-h4mf-4v27-hggj (medium) — rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
GHSA-h4mf-4v27-hggj Severity: medium CVE: None
rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect
## 1. Summary
WebDAV's default redirect handling can replay Basic authorization and configured Cookie headers over plaintext HTTP after a same-host HTTPS-to-HTTP redirect. This was reproduced through the real backend. Unlike the low-impact STS token in rclone's published S3 redir
MITRE ATT&CK techniques
Original source: https://github.com/advisories/GHSA-h4mf-4v27-hggj