PT-2021-22372 · Octorpki · Octorpki

Iifiigii

+1

·

Published

2021-11-10

·

Updated

2024-08-21

·

CVE-2021-3907

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OctoRPKI (affected versions not specified)
Description The issue allows a repository to create a file that can be written to disk outside the base cache folder due to a failure to escape a URI with a filename containing "..". This could enable remote code execution on the host machine running OctoRPKI. The vulnerability is related to directory traversal attacks, where the ExtractPathManifest function permits file paths containing relative directory components (".."), allowing files to reference arbitrary locations on the filesystem. For example, a repository could create a file using the rsync://example.org/repo/../../etc/cron.daily/evil.roa URI.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2021-3907
DSA-5033-1
DSA-5041-1
GHSA-3JHM-87M6-X959
GHSA-8459-6RC9-8VF8
GHSA-CQH2-VC2F-Q4FH
GO-2022-0248
GO-2022-0496

Affected Products

Octorpki