Описание
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| dnsdist | fixed | 1.2.0-1 | package | |
| dnsdist | fixed | 1.1.0-2+deb9u1 | stretch | package |
Примечания
https://dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2017-02.html
Patches: https://downloads.powerdns.com/patches/2017-02
Связанные уязвимости
CVSS3: 8.8
ubuntu
больше 8 лет назад
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
CVSS3: 8.8
nvd
больше 8 лет назад
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
CVSS3: 8.8
github
больше 3 лет назад
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.