x/vulndb: potential Go vuln in github.com/cloudflare/cfrpki: CVE-2022-3616 #1089
Labels
excluded: EFFECTIVELY_PRIVATE
This vulnerability exists in a package can be imported, but isn't meant to be outside that module.
CVE-2022-3616 references github.com/cloudflare/cfrpki, which may be a Go module.
Description:
Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequence it would cause the program to crash, preventing it from finishing the validation and leading to a denial of service.
References:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: