QID 980107

QID 980107: Go (go) Security Update for github.com/cloudflare/cfrpki/cmd/octorpki (GHSA-g5gj-9ggf-9vmq)

OctoRPKI does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end.

## Patches

## For more information
If you have any questions or comments about this advisory email us at [email protected]

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-g5gj-9ggf-9vmq for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980107

    Software Advisories
    Advisory ID Software Component Link
    GHSA-g5gj-9ggf-9vmq github.com/cloudflare/cfrpki/cmd/octorpki URL Logo github.com/advisories/GHSA-g5gj-9ggf-9vmq