Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-3806

Опубликовано: 29 янв. 2019
Источник: nvd
CVSS3: 5.4
CVSS3: 8.1
CVSS2: 6.8
EPSS Низкий

Описание

An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:powerdns:recursor:*:*:*:*:*:*:*:*
Версия от 4.1.4 (включая) до 4.1.9 (исключая)

EPSS

Процентиль: 6%
0.00024
Низкий

5.4 Medium

CVSS3

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-358
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 7 лет назад

An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua.

CVSS3: 8.1
debian
около 7 лет назад

An issue has been found in PowerDNS Recursor versions after 4.1.3 befo ...

CVSS3: 8.1
github
больше 3 лет назад

An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua.

EPSS

Процентиль: 6%
0.00024
Низкий

5.4 Medium

CVSS3

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-358
NVD-CWE-noinfo