Skip to content
This repository has been archived by the owner on Jun 9, 2024. It is now read-only.

OctoRPKI crashes when max iterations is reached

Moderate
mskowroncf published GHSA-pmw9-567p-68pc Oct 28, 2022

Package

gomod github.com/cloudflare/cfrpki/cmd/octorpki (Go)

Affected versions

<= 1.4.3

Patched versions

1.4.4

Description

Impact

Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter that would cause the program to crash and not finish the validation and thus a denial of service.

Patches

This issue is fixed in v1.4.4

Workarounds

None.

Severity

Moderate

CVE ID

CVE-2022-3616

Weaknesses

No CWEs