#VU103643 Reliance on Reverse DNS Resolution for a Security-Critical Action in Lightbend - CVE-2023-31442
Published: February 5, 2025
Lightbend
Akka Project
Description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to async-dns resolver (used by Discovery in DNS mode and transitively by Cluster Bootstrap) uses predictable DNS transaction IDs when resolving DNS records. A remote attacker can exploit the vulnerability to perform a denial of service attack.