Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3907

Опубликовано: 11 нояб. 2021
Источник: debian

Описание

OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cfrpkifixed1.4.0-1package
fort-validatorfixed1.5.3-1package

Примечания

  • https://github.com/cloudflare/cfrpki/security/advisories/GHSA-cqh2-vc2f-q4fh

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 4 лет назад

OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.

CVSS3: 7.4
nvd
около 4 лет назад

OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.

CVSS3: 7.4
github
около 4 лет назад

Arbitrary filepath traversal via URI injection