PT-2024-12162 · Coredns · Coredns

Xiang Li

·

Published

2024-09-18

·

Updated

2024-09-27

·

CVE-2023-28452

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CoreDNS versions through 1.10.1
Description An issue was discovered in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing denial of service for normal resolution. In an exploit, the attacker could forge a response targeting the source port of a vulnerable resolver without the need to guess the correct TXID.
Recommendations For CoreDNS versions through 1.10.1, update to a version later than 1.10.1 to resolve the issue. At the moment, there is no information about additional mitigation measures for this vulnerability.

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-28452
ECHO-7DF6-6E5E-506B
GHSA-HFMW-7G3M-GJ6Q
GO-2024-3130
OPENSUSE-SU-2024:0319-1

Affected Products

Coredns