NA

CVE-2023-0158

Published: 17/01/2023 Updated: 24/01/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

NLnet Labs Krill supports direct access to the RRDP repository content through its built-in web server at the "/rrdp" endpoint. before 0.12.1 a direct query for any existing directory under "/rrdp/", rather than an RRDP file such as "/rrdp/notification.xml" as would be expected, causes Krill to crash. If the built-in "/rrdp" endpoint is exposed directly to the internet, then malicious remote parties can cause the publication server to crash. The repository content is not affected by this, but the availability of the server and repository can cause issues if this attack is persistent and is not mitigated.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nlnetlabs krill

Github Repositories

RPKI Certificate Authority and Publication Server written in Rust

Krill Krill is a Resource Public Key Infrastructure (RPKI) daemon, featuring a Certificate Authority (CA) and publication server, written in Rust If you have any feedback, we would love to hear from you Don’t hesitate to create an issue on Github or post a message on our RPKI mailing list or Discord server For more information please refer to the documentation Public