QID 980108

QID 980108: Go (go) Security Update for github.com/cloudflare/cfrpki (GHSA-cqh2-vc2f-q4fh)

OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. `rsync://example.org/repo/../../etc/cron.daily/evil.roa`), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.

## Patches

## For more information
If you have any questions or comments about this advisory email us at [email protected]

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-cqh2-vc2f-q4fh for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980108

    Software Advisories
    Advisory ID Software Component Link
    GHSA-cqh2-vc2f-q4fh github.com/cloudflare/cfrpki URL Logo github.com/advisories/GHSA-cqh2-vc2f-q4fh
    GHSA-cqh2-vc2f-q4fh github.com/cloudflare/cfrpki/cmd/octorpki URL Logo github.com/advisories/GHSA-cqh2-vc2f-q4fh