Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2286 | When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided service definition defaults to root ( https://github.com/cloudflare/cfrpki/blob/master/package/octorpki.service ) this could allow for a vector, when combined with another vulnerability that causes octorpki to process a malicious TAL file, for a local privilege escalation. |
Github GHSA |
GHSA-3pqh-p72c-fj85 | Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki |
Tue, 29 Jul 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:cloudflare:octorpki:*:*:*:*:*:*:*:* |
Wed, 12 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Jan 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When copying files with rsync, octorpki uses the "-a" flag 0, which forces rsync to copy binaries with the suid bit set as root. Since the provided service definition defaults to root ( https://github.com/cloudflare/cfrpki/blob/master/package/octorpki.service ) this could allow for a vector, when combined with another vulnerability that causes octorpki to process a malicious TAL file, for a local privilege escalation. | |
| Title | Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cloudflare
Published:
Updated: 2025-02-12T16:03:40.405Z
Reserved: 2021-11-18T20:10:42.977Z
Link: CVE-2021-3978
Updated: 2025-02-12T16:03:34.945Z
Status : Analyzed
Published: 2025-01-29T10:15:07.750
Modified: 2025-07-29T23:40:21.880
Link: CVE-2021-3978
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:45:00Z
EUVD
Github GHSA