Количество 4
Количество 4
CVE-2021-3907
OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.
CVE-2021-3907
OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.
CVE-2021-3907
OctoRPKI does not escape a URI with a filename containing "..", this a ...
GHSA-cqh2-vc2f-q4fh
Arbitrary filepath traversal via URI injection
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-3907 OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on. | CVSS3: 7.4 | 1% Низкий | около 4 лет назад | |
CVE-2021-3907 OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on. | CVSS3: 7.4 | 1% Низкий | около 4 лет назад | |
CVE-2021-3907 OctoRPKI does not escape a URI with a filename containing "..", this a ... | CVSS3: 7.4 | 1% Низкий | около 4 лет назад | |
GHSA-cqh2-vc2f-q4fh Arbitrary filepath traversal via URI injection | CVSS3: 7.4 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу