GHSA-5rxf-fqch-7vqp

Suggest an improvement
Source
https://github.com/advisories/GHSA-5rxf-fqch-7vqp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-5rxf-fqch-7vqp/GHSA-5rxf-fqch-7vqp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5rxf-fqch-7vqp
Aliases
Published
2023-09-13T15:31:14Z
Modified
2025-10-03T15:12:28Z
Severity
  • 9.3 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H CVSS Calculator
Summary
NLnet Labs’ Routinator vulnerable to path traversal
Details

NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it.

Database specific
{
    "cwe_ids":  [
        "CWE-22",
        "CWE-35"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-10-03T14:21:45Z",
    "nvd_published_at":  "2023-09-13T15:15:07Z",
    "severity":  "CRITICAL"
}
References

Affected packages

crates.io / routinator

Package

Name
routinator
View open source insights on deps.dev
Purl
pkg:cargo/routinator

Affected ranges

Type
SEMVER
Events
Introduced
0.9.0
Fixed
0.12.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-5rxf-fqch-7vqp/GHSA-5rxf-fqch-7vqp.json"