Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki
Description
Reviewed
Nov 19, 2021
Published to the GitHub Advisory Database
Nov 19, 2021
Published by the National Vulnerability Database
Jan 29, 2025
Last updated
Jan 29, 2025
Impact
When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided service definition defaults to root (https://github.com/cloudflare/cfrpki/blob/master/package/octorpki.service) this could allow for a vector, when combined with another vulnerability that causes octorpki to process a malicious TAL file, for a local privilege escalation.
For more information
If you have any questions or comments about this advisory email us at security@cloudflare.com
References