Skip to content

x/vulndb: potential Go vuln in github.com/cloudflare/cfrpki/cmd/octorpki: GHSA-8459-6rc9-8vf8 #362

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
GoVulnBot opened this issue Mar 24, 2022 · 4 comments
Assignees

Comments

@GoVulnBot
Copy link

In GitHub Security Advisory GHSA-8459-6rc9-8vf8, there is a vulnerability in the following Go packages or modules:

Unit Fixed Vulnerable Ranges
github.com/cloudflare/cfrpki/cmd/octorpki <= 1.4.2

See doc/triage.md for instructions on how to triage this report.

package: github.com/cloudflare/cfrpki/cmd/octorpki
versions:
  - introduced: v0.0.0
description: "### Impact\n\nIn the case that a malicious TAL file is parsed pointing
    to a repository that provides a malicious ROA file which octorpki downloads, it
    is possible to bypass the current directory traversal mitigation to allow writing
    outside of the current directory. \n\n### Patches\n\nNo patch release has been
    made"
published: 2022-02-14T22:52:15Z
last_modified: 2022-02-15T00:14:52Z
ghsas:
  - GHSA-8459-6rc9-8vf8

@neild
Copy link
Contributor

neild commented Jul 13, 2022

Duplicate of #248.

@neild neild closed this as completed Jul 13, 2022
@neild neild assigned neild and unassigned rolandshoemaker Jul 13, 2022
@tatianab
Copy link
Contributor

Duplicate of #248

@tatianab tatianab marked this as a duplicate of #248 Jul 25, 2022
@tatianab
Copy link
Contributor

@neild is this actually a duplicate of #248? To me they look like two separate issues...

@tatianab tatianab reopened this Jul 28, 2023
@gopherbot
Copy link
Contributor

Change https://go.dev/cl/539338 mentions this issue: data/reports: update GO-2022-0248 to include later fix

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

6 participants