VDB
Sign up
LOW

GHSA-8459-6rc9-8vf8

Path traversal in github.com/cloudflare/cfrpki/cmd/octorpki

Quick fix

GHSA-8459-6rc9-8vf8 — github.com/cloudflare/cfrpki: upgrade to the fixed version with the command below.

go get github.com/cloudflare/cfrpki@v1.4.3

Details

### Impact

In the case that a malicious TAL file is parsed pointing to a repository that provides a malicious ROA file which octorpki downloads, it is possible to bypass the current directory traversal mitigation to allow writing outside of the current directory.

### Patches

No patch release has been made

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/cloudflare/cfrpki
Introduced in: 0Fixed in: 1.4.3
Fixgo get github.com/cloudflare/cfrpki@v1.4.3

References