Description
OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to 1.4.3
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5033-1 | fort-validator security update |
Debian DSA |
DSA-5041-1 | cfrpki security update |
EUVD |
EUVD-2021-2338 | OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on. |
Github GHSA |
GHSA-cqh2-vc2f-q4fh | Arbitrary filepath traversal via URI injection |
References
History
No history.
Status: PUBLISHED
Assigner: cloudflare
Published:
Updated: 2024-09-17T03:18:30.852Z
Reserved: 2021-10-26T00:00:00.000Z
Link: CVE-2021-3907
No data.
Status : Modified
Published: 2021-11-11T22:15:07.820
Modified: 2024-11-21T06:22:45.000
Link: CVE-2021-3907
No data.
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Github GHSA