Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xhxv-xr8w-7xpm

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.

Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.

EPSS

Процентиль: 83%
0.01978
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 8 лет назад

Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.

CVSS3: 5.9
nvd
больше 8 лет назад

Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.

CVSS3: 5.9
debian
больше 8 лет назад

Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within th ...

suse-cvrf
больше 5 лет назад

Security update for knot

suse-cvrf
больше 5 лет назад

Security update for knot

EPSS

Процентиль: 83%
0.01978
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-20