Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8459-6rc9-8vf8

Опубликовано: 14 фев. 2022
Источник: github
Github: Прошло ревью

Описание

Path traversal in github.com/cloudflare/cfrpki/cmd/octorpki

Impact

In the case that a malicious TAL file is parsed pointing to a repository that provides a malicious ROA file which octorpki downloads, it is possible to bypass the current directory traversal mitigation to allow writing outside of the current directory.

Patches

No patch release has been made

Пакеты

Наименование

github.com/cloudflare/cfrpki

go
Затронутые версииВерсия исправления

<= 1.4.2

1.4.3

Дефекты

CWE-22

Дефекты

CWE-22