PT-2024-12162 · Coredns · Coredns
Xiang Li
·
Published
2024-09-18
·
Updated
2024-09-27
·
CVE-2023-28452
CVSS v4.0
8.2
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CoreDNS versions through 1.10.1
Description
An issue was discovered in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing denial of service for normal resolution. In an exploit, the attacker could forge a response targeting the source port of a vulnerable resolver without the need to guess the correct TXID.
Recommendations
For CoreDNS versions through 1.10.1, update to a version later than 1.10.1 to resolve the issue.
At the moment, there is no information about additional mitigation measures for this vulnerability.
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coredns