Vulnerabilities
Vulnerable Software
Cloudflare:  >> Octorpki  >> 1.3.0  Security Vulnerabilities
When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided service definition defaults to root ( https://github.com/cloudflare/cfrpki/blob/master/package/octorpki.service ) this could allow for a vector, when combined with another vulnerability that causes octorpki to process a malicious TAL file, for a local privilege escalation.
CVSS Score
7.5
EPSS Score
0.0
Published
2025-01-29
Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequence it would cause the program to crash, preventing it from finishing the validation and leading to a denial of service. Credits to Donika Mirdita and Haya Shulman - Fraunhofer SIT, ATHENE, who discovered and reported this vulnerability.
CVSS Score
5.4
EPSS Score
0.001
Published
2022-10-28


Contact Us

Shodan ® - All rights reserved