Логотип exploitDog
bind:CVE-2023-32077
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-32077

Количество 2

Количество 2

nvd логотип

CVE-2023-32077

больше 2 лет назад

Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in Netmaker allowing unauth users to interact with DNS API endpoints. The issue is patched in 0.17.1 and fixed in 0.18.6. If users are using 0.17.1, they should run `docker pull gravitl/netmaker:v0.17.1` and `docker-compose up -d`. This will switch them to the patched users. If users are using v0.18.0-0.18.5, they should upgrade to v0.18.6 or later. As a workaround, someone who is using version 0.17.1 can pull the latest docker image of the backend and restart the server.

CVSS3: 7.5
EPSS: Высокий
github логотип

GHSA-8x8h-hcq8-jwwx

больше 2 лет назад

Netmaker has Hardcoded DNS Secret Key

CVSS3: 7.5
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-32077

Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in Netmaker allowing unauth users to interact with DNS API endpoints. The issue is patched in 0.17.1 and fixed in 0.18.6. If users are using 0.17.1, they should run `docker pull gravitl/netmaker:v0.17.1` and `docker-compose up -d`. This will switch them to the patched users. If users are using v0.18.0-0.18.5, they should upgrade to v0.18.6 or later. As a workaround, someone who is using version 0.17.1 can pull the latest docker image of the backend and restart the server.

CVSS3: 7.5
85%
Высокий
больше 2 лет назад
github логотип
GHSA-8x8h-hcq8-jwwx

Netmaker has Hardcoded DNS Secret Key

CVSS3: 7.5
85%
Высокий
больше 2 лет назад

Уязвимостей на страницу