Input validation error in CoreDNS - CVE-2024-0874

 

Input validation error in CoreDNS - CVE-2024-0874

Published: June 28, 2024


Vulnerability identifier: #VU93499
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-0874
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to incorrect implementation of cashing. A remote attacker can force the DNS server to return invalid cache entries and perform spoofing attack.


Affected software

CoreDNS
IBM Cloud Pak for Watson AIOps
Red Hat OpenShift Container Platform

How to mitigate CVE-2024-0874

Install updates from vendor's website.

CoreDNS - update to 1.11.3
IBM Cloud Pak for Watson AIOps - update to 4.8.0
Red Hat OpenShift Container Platform - addressed in versions 4.13.49, 4.14.36, 4.15.24, 4.16.0

External References

Related Security Bulletins