Path traversal in github.com/cloudflare/cfrpki/cmd/octorpki
Package
Affected versions
<= 1.4.2
Patched versions
1.4.3
Description
Published to the GitHub Advisory Database
Feb 14, 2022
Reviewed
Feb 14, 2022
Last updated
Nov 7, 2023
Impact
In the case that a malicious TAL file is parsed pointing to a repository that provides a malicious ROA file which octorpki downloads, it is possible to bypass the current directory traversal mitigation to allow writing outside of the current directory.
Patches
No patch release has been made
References