CVE-2021-3978
HIGHcloudflare/octorpki < 1.4.2 - Local Privilege Escalation via rsync suid Bit Handling
Title source: llmDescription
When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided service definition defaults to root ( https://github.com/cloudflare/cfrpki/blob/master/package/octorpki.service ) this could allow for a vector, when combined with another vulnerability that causes octorpki to process a malicious TAL file, for a local privilege escalation.
References (1)
Core 1
Core References
Scores
CVSS v3
7.5
EPSS
0.0014
EPSS Percentile
3.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-269
Status
published
Products (2)
cloudflare/cfrpki
0 - 1.4.2Go
cloudflare/octorpki
< 1.4.2
Published
Jan 29, 2025
Tracked Since
Feb 18, 2026