ZeroHour

CVE-2022-3616

CVSS 3.1
7.5 high
EPSS
<1%p36
Published
()
Modified
Description

Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequence it would cause the program to crash, preventing it from finishing the validation and leading to a denial of service. Credits to Donika Mirdita and Haya Shulman - Fraunhofer SIT, ATHENE, who discovered and reported this vulnerability.

Vendors
cloudflare
Products
octorpki
Weakness
CWE-754, CWE-834
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.