Information disclosure in PowerDNS Authoritative - CVE-2020-17482
Published: September 28, 2020
PowerDNS Authoritative
PowerDNS.COM B.V.
Description
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory. Such a user could be a customer inserting data via a control panel, or somebody with access to the REST API.