Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c6vq-q4cf-9cgj

Опубликовано: 31 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.1

Описание

An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI.

An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI.

EPSS

Процентиль: 3%
0.00136
Низкий

3.1 Low

CVSS3

Дефекты

CWE-80

Связанные уязвимости

CVSS3: 3.1
ubuntu
5 месяцев назад

An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI.

CVSS3: 3.1
nvd
5 месяцев назад

An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI.

CVSS3: 3.1
debian
5 месяцев назад

An attacker might be able to inject HTML content into the internal web ...

CVSS3: 4.3
redos
19 дней назад

Уязвимость dnsdist

CVSS3: 4.3
redos
19 дней назад

Уязвимость dnsdist

EPSS

Процентиль: 3%
0.00136
Низкий

3.1 Low

CVSS3

Дефекты

CWE-80