Vulnerability Details CVE-2021-3907
OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.022
EPSS Ranking 83.8%
CVSS Severity
CVSS v3 Score 7.4
CVSS v2 Score 7.5
Products affected by CVE-2021-3907
-
cpe:2.3:a:cloudflare:octorpki:-
-
cpe:2.3:a:cloudflare:octorpki:1.0.0
-
cpe:2.3:a:cloudflare:octorpki:1.0.1
-
cpe:2.3:a:cloudflare:octorpki:1.0.2
-
cpe:2.3:a:cloudflare:octorpki:1.0.3
-
cpe:2.3:a:cloudflare:octorpki:1.1.0
-
cpe:2.3:a:cloudflare:octorpki:1.1.1
-
cpe:2.3:a:cloudflare:octorpki:1.1.2
-
cpe:2.3:a:cloudflare:octorpki:1.1.3
-
cpe:2.3:a:cloudflare:octorpki:1.1.4
-
cpe:2.3:a:cloudflare:octorpki:1.2.0
-
cpe:2.3:a:cloudflare:octorpki:1.2.1
-
cpe:2.3:a:cloudflare:octorpki:1.2.2
-
cpe:2.3:o:debian:debian_linux:10.0
-
cpe:2.3:o:debian:debian_linux:11.0