Логотип exploitDog
bind:CVE-2021-3907
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-3907

Количество 4

Количество 4

ubuntu логотип

CVE-2021-3907

около 4 лет назад

OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2021-3907

около 4 лет назад

OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2021-3907

около 4 лет назад

OctoRPKI does not escape a URI with a filename containing "..", this a ...

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-cqh2-vc2f-q4fh

около 4 лет назад

Arbitrary filepath traversal via URI injection

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-3907

OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.

CVSS3: 7.4
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-3907

OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.

CVSS3: 7.4
1%
Низкий
около 4 лет назад
debian логотип
CVE-2021-3907

OctoRPKI does not escape a URI with a filename containing "..", this a ...

CVSS3: 7.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-cqh2-vc2f-q4fh

Arbitrary filepath traversal via URI injection

CVSS3: 7.4
1%
Низкий
около 4 лет назад

Уязвимостей на страницу