GHSA-8459-6rc9-8vf8

    Dashboard / Vulnerabilities / GHSA-8459-6rc9-8vf8

    GHSA-8459-6rc9-8vf8

    Published: 14 Feb 2022Last Modified: 14 Jan 2025

    Summary: Path traversal in github.com/cloudflare/cfrpki/cmd/octorpki

    Details: ### Impact In the case that a malicious TAL file is parsed pointing to a repository that provides a malicious ROA file which octorpki downloads, it is possible to bypass the current directory traversal mitigation to allow writing outside of the current directory. ### Patches No patch release has been made

    Affected packages

    Package

    Name: github.com/cloudflare/cfrpki

    Purl: pkg:golang/github.com/cloudflare/cfrpki

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.4.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-8459-6rc9-8vf8 | CVE-DB