Infinite certificate chain depth results in OctoRPKI running forever
Description
Reviewed
Nov 10, 2021
Published to the GitHub Advisory Database
Nov 10, 2021
Published by the National Vulnerability Database
Nov 11, 2021
Last updated
Oct 2, 2023
OctoRPKI (github.com/cloudflare/cfrpki/cmd/octorpki) does not limit the depth of a certificate chain, allowing for a CA to create children in an ad-hoc fashion, thereby making tree traversal never end.
For more information
If you have any questions or comments about this advisory email us at [email protected]
References