{"id":"GHSA-8459-6rc9-8vf8","summary":"Path traversal in github.com/cloudflare/cfrpki/cmd/octorpki","details":"### Impact\n\nIn the case that a malicious TAL file is parsed pointing to a repository that provides a malicious ROA file which octorpki downloads, it is possible to bypass the current directory traversal mitigation to allow writing outside of the current directory. \n\n### Patches\n\nNo patch release has been made","aliases":["CVE-2021-3907","GHSA-cqh2-vc2f-q4fh","GO-2022-0248"],"modified":"2025-01-08T08:26:59.465873Z","published":"2022-02-14T22:52:15Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-02-14T22:52:15Z","nvd_published_at":null,"cwe_ids":["CWE-22"],"severity":"LOW"},"references":[{"type":"WEB","url":"https://github.com/cloudflare/cfrpki/security/advisories/GHSA-8459-6rc9-8vf8"},{"type":"WEB","url":"https://github.com/cloudflare/cfrpki/commit/a053a808feeb3115c76b6cc263ee55598ce6e8cd"},{"type":"WEB","url":"https://github.com/cloudflare/cfrpki/commit/eb9cc4db7b7b79e44f56dfaa959fccdfb2af8284"},{"type":"PACKAGE","url":"https://github.com/cloudflare/cfrpki"},{"type":"WEB","url":"https://github.com/cloudflare/cfrpki/releases/tag/v1.4.3"}],"affected":[{"package":{"name":"github.com/cloudflare/cfrpki","ecosystem":"Go","purl":"pkg:golang/github.com/cloudflare/cfrpki"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.4.3"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.4.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-8459-6rc9-8vf8/GHSA-8459-6rc9-8vf8.json"}}],"schema_version":"1.9.0"}