Lucene search

K
cvelistCloudflareCVELIST:CVE-2021-3907
HistoryNov 11, 2021 - 9:45 p.m.

CVE-2021-3907 Arbitrary filepath traversal via URI injection

2021-11-1121:45:16
CWE-20
CWE-22
cloudflare
www.cve.org
3
cve-2021-3907
filepath traversal
uri injection
remote code execution
octorpki security concern

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

AI Score

9.9

Confidence

High

EPSS

0.068

Percentile

94.0%

OctoRPKI does not escape a URI with a filename containing “…”, this allows a repository to create a file, (ex. rsync://example.org/repo/…/…/etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.

CNA Affected

[
  {
    "product": "octorpki",
    "vendor": "Cloudflare",
    "versions": [
      {
        "lessThan": "1.4.3",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

AI Score

9.9

Confidence

High

EPSS

0.068

Percentile

94.0%