GHSA-gx4c-2hqx-cw2r: rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect
Disclosure of the AWS STS session token (X-Amz-Security-Token) in
cleartext for the remainder of its validity window. This is the exact class
of leak that e7b1eb774 was written to close — it just doesn’t cover the
scheme-downgrade axis of “crossing a host”.
References
Code Behaviors & Features
Detect and mitigate GHSA-gx4c-2hqx-cw2r with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →