PT-2021-22372 · Octorpki · Octorpki
Iifiigii
+1
·
Published
2021-11-10
·
Updated
2024-08-21
·
CVE-2021-3907
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
OctoRPKI (affected versions not specified)
Description
The issue allows a repository to create a file that can be written to disk outside the base cache folder due to a failure to escape a URI with a filename containing "..". This could enable remote code execution on the host machine running OctoRPKI. The vulnerability is related to directory traversal attacks, where the
ExtractPathManifest function permits file paths containing relative directory components (".."), allowing files to reference arbitrary locations on the filesystem. For example, a repository could create a file using the rsync://example.org/repo/../../etc/cron.daily/evil.roa URI.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Octorpki