UNKNOWN Go
Path traversal in github.com/cloudflare/cfrpki/cmd/octorpki
GHSA-8459-6rc9-8vf8 · CVE-2021-3907 · GHSA-cqh2-vc2f-q4fh · GO-2022-0248
Published · Modified
Description
Impact
In the case that a malicious TAL file is parsed pointing to a repository that provides a malicious ROA file which octorpki downloads, it is possible to bypass the current directory traversal mitigation to allow writing outside of the current directory.
Patches
No patch release has been made
References
- WEB https://github.com/cloudflare/cfrpki/security/advisories/GHSA-8459-6rc9-8vf8
- WEB https://github.com/cloudflare/cfrpki/commit/a053a808feeb3115c76b6cc263ee55598ce6e8cd
- WEB https://github.com/cloudflare/cfrpki/commit/eb9cc4db7b7b79e44f56dfaa959fccdfb2af8284
- PACKAGE https://github.com/cloudflare/cfrpki
- WEB https://github.com/cloudflare/cfrpki/releases/tag/v1.4.3
Ready to move
Start Securing
Free, no credit card | First findings in minutes