{"id":"CVE-2021-3907","aliases":["GHSA-8459-6rc9-8vf8","GHSA-cqh2-vc2f-q4fh","GO-2022-0248"],"url":"https://o3.security/vulnerability/CVE-2021-3907","summary":"Path traversal in github.com/cloudflare/cfrpki/cmd/octorpki","details":"### Impact\n\nIn the case that a malicious TAL file is parsed pointing to a repository that provides a malicious ROA file which octorpki downloads, it is possible to bypass the current directory traversal mitigation to allow writing outside of the current directory. \n\n### Patches\n\nNo patch release has been made","published":"2021-11-11T22:15:07.820Z","modified":"2026-07-08T06:00:41.237494390Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/cloudflare/cfrpki","fixedVersion":"1.4.3"}],"fix":{"url":"https://github.com/cloudflare/cfrpki/commit/a053a808feeb3115c76b6cc263ee55598ce6e8cd","label":"cloudflare/cfrpki@a053a80"},"references":[{"type":"ADVISORY","url":"https://github.com/cloudflare/cfrpki/security/advisories/GHSA-3jhm-87m6-x959"},{"type":"ADVISORY","url":"https://github.com/cloudflare/cfrpki/security/advisories/GHSA-cqh2-vc2f-q4fh"},{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-5033"},{"type":"ADVISORY","url":"https://www.debian.org/security/2022/dsa-5041"},{"type":"WEB","url":"https://github.com/cloudflare/cfrpki/security/advisories/GHSA-8459-6rc9-8vf8"},{"type":"WEB","url":"https://github.com/cloudflare/cfrpki/commit/a053a808feeb3115c76b6cc263ee55598ce6e8cd"},{"type":"WEB","url":"https://github.com/cloudflare/cfrpki/commit/eb9cc4db7b7b79e44f56dfaa959fccdfb2af8284"},{"type":"PACKAGE","url":"https://github.com/cloudflare/cfrpki"},{"type":"WEB","url":"https://github.com/cloudflare/cfrpki/releases/tag/v1.4.3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T06:00:41.237494390Z"}}