Vulnerability Database
Blog
FAQ
Docs
GO-2022-0496
See a problem?
Source
https://pkg.go.dev/vuln/GO-2022-0496
Import Source
https://vuln.go.dev/ID/GO-2022-0496.json
JSON Data
https://api.osv.dev/v1/vulns/GO-2022-0496
Aliases
CVE-2021-3907
GHSA-3jhm-87m6-x959
GHSA-8459-6rc9-8vf8
GHSA-cqh2-vc2f-q4fh
GO-2022-0248
Published
2024-08-21T15:11:33Z
Modified
2024-08-21T15:41:41.341758Z
Summary
Path traversal mitigation bypass in OctoRPKI in github.com/cloudflare/cfrpki
Details
Path traversal mitigation bypass in OctoRPKI in github.com/cloudflare/cfrpki
References
https://github.com/cloudflare/cfrpki/security/advisories/GHSA-3jhm-87m6-x959
https://github.com/cloudflare/cfrpki/releases/tag/v1.4.3
https://github.com/cloudflare/cfrpki/security/advisories/GHSA-cqh2-vc2f-q4fh
https://nvd.nist.gov/vuln/detail/CVE-2021-3907
Affected packages
Go
/
github.com/cloudflare/cfrpki
Package
Name
github.com/cloudflare/cfrpki
View open source insights on deps.dev
Purl
pkg:golang/github.com/cloudflare/cfrpki
Affected ranges
Type
SEMVER
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
1.4.3
GO-2022-0496 - OSV