UNKNOWN Go

Path traversal mitigation bypass in OctoRPKI

GHSA-3jhm-87m6-x959 · GO-2022-0496

Published · Modified

Description

Impact

The existing URI path filters in OctoRPKI (version < 1.4.3) mitigating Path traversal vulnerability could be bypassed by an attacker. In case a malicious TAL file is parsed, it was possible to write files outside the base cache folder.

Specific Go Packages Affected

github.com/cloudflare/cfrpki/cmd/octorpki

Patches

The issue was fixed in version 1.4.3

References

CVE-2021-3907

Ready to move

Start Securing

Free, no credit card | First findings in minutes