PT-2024-10117 · Coredns+1 · Coredns+1

Govulnbot

+1

·

Published

2024-04-25

·

Updated

2025-01-10

·

CVE-2024-0874

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions coredns (affected versions not specified)
Description The issue is related to information disclosure via caching in the coredns DNS server. It could allow a remote attacker to conduct spoofing attacks due to incorrectly implemented caching, leading to invalid cache entries being returned.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-40201
AZL-40222
BDU:2025-00341
CVE-2024-0874
ECHO-DEFF-F49A-144E
GHSA-M9W6-WP3H-VQ8G
GO-2024-2785
OPENSUSE-SU-2024:0319-1
OPENSUSE-SU-2024:13620-1

Affected Products

Red Os
Coredns