CVE-2022-3616
published 2022-10-28CVE-2022-3616: Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequence it would cause the program to crash…
PriorityP432high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.40%
33.1th percentile
Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequence it would cause the program to crash, preventing it from finishing the validation and leading to a denial of service. Credits to Donika Mirdita and Haya Shulman - Fraunhofer SIT, ATHENE, who discovered and reported this vulnerability.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cloudflare | octorpki | < <1.4.4 | <1.4.4 |
| cloudflare | octorpki | < 1.4.4 | 1.4.4 |
| debian | cfrpki | < cfrpki 1.4.4-1 (bookworm) | cfrpki 1.4.4-1 (bookworm) |
| github.com | cloudflare_cfrpki | >= 0 < 1.4.4 | 1.4.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki
osv·2024-08-21
CVE-2022-3616 OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki
OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki
OctoRPKI crashes when max iterations is reached in github.com/cloudflare/cfrpki
GHSA
OctoRPKI crashes when max iterations is reached
ghsa·2022-10-31
CVE-2022-3616 [MEDIUM] CWE-754 OctoRPKI crashes when max iterations is reached
OctoRPKI crashes when max iterations is reached
### Impact
Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequence it would cause the program to crash, preventing it from finishing the validation and leading to a denial of service. Credits to Donika Mirdita and Haya Shulman - Fraunhofer SIT, ATHENE, who discovered and reported this vulnerability.
### Specific Go Packages Affected
github.com/cloudflare/cfrpki/cmd/octorpki
### Patches
This issue is fixed in v1.4.4
### Workarounds
None.
OSV
OctoRPKI crashes when max iterations is reached
osv·2022-10-31
CVE-2022-3616 [MEDIUM] OctoRPKI crashes when max iterations is reached
OctoRPKI crashes when max iterations is reached
### Impact
Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequence it would cause the program to crash, preventing it from finishing the validation and leading to a denial of service. Credits to Donika Mirdita and Haya Shulman - Fraunhofer SIT, ATHENE, who discovered and reported this vulnerability.
### Specific Go Packages Affected
github.com/cloudflare/cfrpki/cmd/octorpki
### Patches
This issue is fixed in v1.4.4
### Workarounds
None.
OSV
CVE-2022-3616: Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter
osv·2022-10-28·CVSS 7.5
CVE-2022-3616 [HIGH] CVE-2022-3616: Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter
Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequence it would cause the program to crash, preventing it from finishing the validation and leading to a denial of service. Credits to Donika Mirdita and Haya Shulman - Fraunhofer SIT, ATHENE, who discovered and reported this vulnerability.
Debian
CVE-2022-3616: cfrpki - Attackers can create long chains of CAs that would lead to OctoRPKI exceeding it...
vendor_debian·2022·CVSS 5.4
CVE-2022-3616 [MEDIUM] CVE-2022-3616: cfrpki - Attackers can create long chains of CAs that would lead to OctoRPKI exceeding it...
Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequence it would cause the program to crash, preventing it from finishing the validation and leading to a denial of service. Credits to Donika Mirdita and Haya Shulman - Fraunhofer SIT, ATHENE, who discovered and reported this vulnerability.
Scope: local
bookworm: resolved (fixed in 1.4.4-1)
bullseye: open
No detection rules found.
No public exploits indexed.
2022-10-28
Published