Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jr65-gpj5-cw74

Опубликовано: 28 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.7

Описание

go-resolver's DNSSEC validation not performed correctly

go-resolver's DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. Root DNSSEC public keys are not validated, permitting an attacker to present a self-signed root key and delegation chain.

Пакеты

Наименование

github.com/peterzen/goresolver

go
Затронутые версииВерсия исправления

<= 1.0.2

Отсутствует

EPSS

Процентиль: 27%
0.00098
Низкий

7.7 High

CVSS3

Дефекты

CWE-345
CWE-347

Связанные уязвимости

CVSS3: 7.5
nvd
около 3 лет назад

DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. Root DNSSEC public keys are not validated, permitting an attacker to present a self-signed root key and delegation chain.

EPSS

Процентиль: 27%
0.00098
Низкий

7.7 High

CVSS3

Дефекты

CWE-345
CWE-347