CVE-2021-3907

HIGH7.4EPSS 1.9%

Arbitrary filepath traversal via URI injection

Published: 6/25/2022Modified: 2/4/2026
Also known as:GHSA-3jhm-87m6-x959GHSA-8459-6rc9-8vf8GHSA-cqh2-vc2f-q4fhGO-2022-0248GO-2022-0496

Description

OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. `rsync://example.org/repo/../../etc/cron.daily/evil.roa`), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on. ## Patches ## For more information If you have any questions or comments about this advisory email us at [email protected]

Affected packages (7)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

References (12)