icon

We found results for “

WS-2022-0164

Good to know:

icon

Date: June 25, 2022

Path traversal mitigation bypass in OctoRPKI.The existing URI path filters in OctoRPKI (version < 1.4.3) mitigating Path traversal vulnerability could be bypassed by an attacker. In case a malicious TAL file is parsed, it was possible to write files outside the base cache folder.

Language: Go

Severity Score

Severity Score

Weakness Type (CWE)

Path Traversal: '.../...//'

CWE-35

Top Fix

icon

Upgrade Version

Upgrade to version v1.4.3

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): HIGH
Availability (A): NONE

Do you need more information?

Contact Us