Possible path traversal when storing RRDP responses
CVE-2023-39916
9.3CRITICAL
What is CVE-2023-39916?
NLnet Labs' Routinator versions 0.9.0 through 0.12.1 expose a vulnerability that could allow an attacker to perform path traversal through the keep-rrdp-responses feature. This happens because the storage location for responses to RRDP requests is derived from the request URL without adequate sanitization. Consequently, malicious actors could leverage this flaw to store response content outside the intended directory, potentially leading to unauthorized data access.
Affected Version(s)
Routinator 0.9.0 < 0.12.2
Routinator 0.14.*
