CVE-2021-3907
HIGH7.4EPSS 1.9%fort-validator - security update
Published: 6/25/2022Modified: 4/28/2026
Description
OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cron.daily/evil.roa), which would then be written to disk outside the base cache folder. This could allow for remote code execution on the host machine OctoRPKI is running on.
Affected packages (7)
- Debian/cfrpkifrom 0, < 1.4.2-1~deb11u1
- Debian/fort-validatorfrom 0, < 1.5.3-1~deb11u1
- Debian/fort-validatorfrom 0, < 1.5.3-1~deb11u1
- Go/github.com/cloudflare/cfrpkifrom 0, < 1.4.3
- Go/github.com/cloudflare/cfrpkifrom 0, < 1.4.4
- Go/github.com/cloudflare/cfrpkifrom 0, < 1.4.3
- Go/github.com/cloudflare/cfrpkifrom 0, < 1.4.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.4 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H |
References (12)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2021-3907
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2021-3907
- PATCHhttps://github.com/cloudflare/cfrpki
- WEBhttps://github.com/cloudflare/cfrpki/commit/a053a808feeb3115c76b6cc263ee55598ce6e8cd
- WEBhttps://github.com/cloudflare/cfrpki/commit/eb9cc4db7b7b79e44f56dfaa959fccdfb2af8284
- WEBhttps://github.com/cloudflare/cfrpki/releases/tag/v1.4.3
- WEBhttps://github.com/cloudflare/cfrpki/security/advisories/GHSA-3jhm-87m6-x959
- WEBhttps://github.com/cloudflare/cfrpki/security/advisories/GHSA-8459-6rc9-8vf8
- WEBhttps://github.com/cloudflare/cfrpki/security/advisories/GHSA-cqh2-vc2f-q4fh
- WEBhttps://pkg.go.dev/vuln/GO-2022-0248
- WEBhttps://www.debian.org/security/2021/dsa-5033
- WEBhttps://www.debian.org/security/2022/dsa-5041