Aller au contenu

Fiche vulnérabilité

CVE-2021-3907 : faille critique cloudflare octorpki (CVSS 9.8)

Description

OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
11 nov. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • cloudflare octorpki
  • debian debian linux

Références

Rechercher une autre vulnérabilité dans la base CVE