UNKNOWN Go

Path traversal in github.com/cloudflare/cfrpki/cmd/octorpki

GHSA-8459-6rc9-8vf8 · CVE-2021-3907 · GHSA-cqh2-vc2f-q4fh · GO-2022-0248

Published · Modified

Description

Impact

In the case that a malicious TAL file is parsed pointing to a repository that provides a malicious ROA file which octorpki downloads, it is possible to bypass the current directory traversal mitigation to allow writing outside of the current directory.

Patches

No patch release has been made

Ready to move

Start Securing

Free, no credit card | First findings in minutes