PT-2021-22373 · Octorpki · Octorpki

Haynespls

·

Published

2021-11-10

·

Updated

2024-08-21

·

CVE-2021-3908

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OctoRPKI (affected versions not specified)
Description The issue arises from OctoRPKI not limiting the depth of a certificate chain, allowing a Certificate Authority (CA) to create children in an ad-hoc manner. This results in tree traversal never ending, causing OctoRPKI to run indefinitely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Infinite Loop

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3908
DSA-5041-1
GHSA-G5GJ-9GGF-9VMQ
GO-2022-0249

Affected Products

Octorpki