LOW
GHSA-8459-6rc9-8vf8
Path traversal in github.com/cloudflare/cfrpki/cmd/octorpki
Quick fix
GHSA-8459-6rc9-8vf8 — github.com/cloudflare/cfrpki: upgrade to the fixed version with the command below.
go get github.com/cloudflare/cfrpki@v1.4.3Details
### Impact
In the case that a malicious TAL file is parsed pointing to a repository that provides a malicious ROA file which octorpki downloads, it is possible to bypass the current directory traversal mitigation to allow writing outside of the current directory.
### Patches
No patch release has been made
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/cloudflare/cfrpki
Introduced in:
0Fixed in: 1.4.3Fix
go get github.com/cloudflare/cfrpki@v1.4.3References
- https://github.com/cloudflare/cfrpki/security/advisories/GHSA-8459-6rc9-8vf8[WEB]
- https://github.com/cloudflare/cfrpki/commit/a053a808feeb3115c76b6cc263ee55598ce6e8cd[WEB]
- https://github.com/cloudflare/cfrpki/commit/eb9cc4db7b7b79e44f56dfaa959fccdfb2af8284[WEB]
- https://github.com/cloudflare/cfrpki[PACKAGE]
- https://github.com/cloudflare/cfrpki/releases/tag/v1.4.3[WEB]