HIGH🇬🇧 English

CVE-2026-49233

CVSS 8.3v4.0pub. 2026-06-08upd. 2026-06-12

Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.

oryginał EN
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Nlnetlabs Routinator

    APP
    Nlnetlabs
    < 0.15.2
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Path Traversal
CWE
Referencje

Powiązane podatności

CVE-2023-39916CRITICAL9.3PL ✓ten sam produkt

Path traversal w NLnet Labs Routinator — zapis odpowiedzi RRDP poza dozwolonym katalogiem

CVE-2026-49234HIGH8.2ten sam produkt

When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endp...

CVE-2026-49235HIGH8.7ten sam produkt

When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator c...

CVE-2024-1622HIGH7.5ten sam produkt

Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the ...

CVE-2023-39915HIGH7.5ten sam produkt

NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPK...