#VU53023 Code injection in Unbound - CVE-2019-25031
Published: May 10, 2021
Unbound
NLnet Labs
Description
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to improper input validation within the contrib/create_unbound_ad_servers.sh script, when retrieving data before writing them into a configuration file. A remote non-authenticated attacker with ability to perform MitM attack can intercept and change Unbound configuration, as the input is retrieved via unencrypted HTTP channel.