CVE-2021-3907
HIGHOctoRPKI < 1.3.0 - Path Traversal and Remote Code Execution via Unsanitized URI Filename
Title source: llmDescription
OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.
References (4)
Core 4
Core References
Third Party Advisory x_refsource_misc
https://github.com/cloudflare/cfrpki/security/advisories/GHSA-cqh2-vc2f-q4fh
Third Party Advisory vendor-advisory
x_refsource_debian
https://www.debian.org/security/2021/dsa-5033
Third Party Advisory vendor-advisory
x_refsource_debian
https://www.debian.org/security/2022/dsa-5041
Third Party Advisory x_refsource_misc
https://github.com/cloudflare/cfrpki/security/advisories/GHSA-3jhm-87m6-x959
Scores
CVSS v3
7.4
EPSS
0.0406
EPSS Percentile
89.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Details
CWE
CWE-20
CWE-22
Status
published
Products (4)
cloudflare/cfrpki
0 - 1.4.4Go
cloudflare/octorpki
< 1.3.0
debian/debian_linux
10.0
debian/debian_linux
11.0
Published
Nov 11, 2021
Tracked Since
Feb 18, 2026