Lucene search

K
osvGoogleOSV:GHSA-8459-6RC9-8VF8
HistoryFeb 14, 2022 - 10:52 p.m.

Path traversal in github.com/cloudflare/cfrpki/cmd/octorpki

2022-02-1422:52:15
Google
osv.dev
10
path traversal
cfrpki
octorpki
repository
roa file
directory traversal
mitigation
software

EPSS

0.068

Percentile

94.0%

Impact

In the case that a malicious TAL file is parsed pointing to a repository that provides a malicious ROA file which octorpki downloads, it is possible to bypass the current directory traversal mitigation to allow writing outside of the current directory.

Patches

No patch release has been made

EPSS

0.068

Percentile

94.0%