UNKNOWN Go
Path traversal mitigation bypass in OctoRPKI
GHSA-3jhm-87m6-x959 · GO-2022-0496
Published · Modified
Description
Impact
The existing URI path filters in OctoRPKI (version < 1.4.3) mitigating Path traversal vulnerability could be bypassed by an attacker. In case a malicious TAL file is parsed, it was possible to write files outside the base cache folder.
Specific Go Packages Affected
github.com/cloudflare/cfrpki/cmd/octorpki
Patches
The issue was fixed in version 1.4.3
References
References
- WEB https://github.com/cloudflare/cfrpki/security/advisories/GHSA-3jhm-87m6-x959
- WEB https://github.com/cloudflare/cfrpki/security/advisories/GHSA-cqh2-vc2f-q4fh
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2021-3907
- PACKAGE https://github.com/cloudflare/cfrpki
- WEB https://github.com/cloudflare/cfrpki/releases/tag/v1.4.3
Ready to move
Start Securing
Free, no credit card | First findings in minutes