cbcvebase.
CVE-2022-3616
published 2022-10-28

CVE-2022-3616: Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequence it would cause the program to crash…

PriorityP432high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.40%
33.1th percentile
Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequence it would cause the program to crash, preventing it from finishing the validation and leading to a denial of service. Credits to Donika Mirdita and Haya Shulman - Fraunhofer SIT, ATHENE, who discovered and reported this vulnerability.

Affected

4 ranges
VendorProductVersion rangeFixed in
cloudflareoctorpki< <1.4.4<1.4.4
cloudflareoctorpki< 1.4.41.4.4
debiancfrpki< cfrpki 1.4.4-1 (bookworm)cfrpki 1.4.4-1 (bookworm)
github.comcloudflare_cfrpki>= 0 < 1.4.41.4.4

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian5.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.