CVE-2023-39916
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 as well as 0.14.0 up to and including 0.14.2 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for RRDP requests. The location of these stored responses is constructed from the URL of the request. Due to insufficient sanitation of the URL, it is possible for an attacker to craft a URL that results in the response being stored outside of the directory specified for it.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H
- EPSS probability
- 0.15%
- CWE
- CWE-35
- Published
- 2023-09-13
- Last modified
- 2026-03-13
Affected products
- NLnet Labs Routinator
- NLnet Labs Routinator
Weakness type
Related vulnerabilities
- CVE-2025-8088 — Path traversal vulnerability in WinRAR
- CVE-2020-26073 — Cisco SD-WAN vManage Directory Traversal Vulnerability
- CVE-2025-24786 — Path traversal opening Sqlite3 database in WhoDB
- CVE-2025-42937 — Directory Traversal vulnerability in SAP Print Service
- CVE-2025-41723 — Sauter: Directory Traversal in importFile SOAP Method
- CVE-2025-30515 — CyberData 011209 SIP Emergency Intercom Path Traversal
- CVE-2023-32714 — Path Traversal in Splunk App for Lookup File Editing
- CVE-2025-53417 — File Parsing Deserialization of Untrusted Data in DTM Soft