PT-2023-27151 · Unknown · Routinator
Donika Mirdita
+7
·
Published
2023-09-13
·
Updated
2025-10-03
·
CVE-2023-39916
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Routinator versions 0.9.0 through 0.12.1
Description
The issue concerns a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature of Routinator. This feature allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it.
Recommendations
For Routinator versions 0.9.0 through 0.12.1, consider disabling the keep-rrdp-responses feature until a patch is available to prevent potential path traversal attacks. Restrict access to the directory where responses are stored to minimize the risk of exploitation. Avoid using the keep-rrdp-responses feature with untrusted RRDP requests until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Routinator