Vulnerability Description
DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. Root DNSSEC public keys are not validated, permitting an attacker to present a self-signed root key and delegation chain.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Go-Resolver Project | Go-Resolver | - |
Related Weaknesses (CWE)
References
- https://github.com/peterzen/goresolver/issues/5#issuecomment-1150214257Issue TrackingThird Party Advisory
- https://pkg.go.dev/vuln/GO-2022-1026Vendor Advisory
- https://github.com/peterzen/goresolver/issues/5#issuecomment-1150214257Issue TrackingThird Party Advisory
- https://pkg.go.dev/vuln/GO-2022-1026Vendor Advisory
FAQ
What is CVE-2022-3347?
CVE-2022-3347 is a vulnerability with a CVSS score of 7.5 (HIGH). DNSSEC validation is not performed correctly. An attacker can cause this package to report successful validation for invalid, attacker-controlled records. Root DNSSEC public keys are not validated, pe...
How severe is CVE-2022-3347?
CVE-2022-3347 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-3347?
Check the references section above for vendor advisories and patch information. Affected products include: Go-Resolver Project Go-Resolver.