Vulnerability Description
An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing denial of service for normal resolution. In an exploit, the attacker could just forge a response targeting the source port of a vulnerable resolver without the need to guess the correct TXID.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Coredns.Io | Coredns | <= 1.10.1 |
Related Weaknesses (CWE)
References
- https://coredns.io/Product
- https://gist.github.com/idealeer/e41c7fb3b661d4262d0b6f21e12168baThird Party Advisory
FAQ
What is CVE-2023-28452?
CVE-2023-28452 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing denial of service for normal re...
How severe is CVE-2023-28452?
CVE-2023-28452 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-28452?
Check the references section above for vendor advisories and patch information. Affected products include: Coredns.Io Coredns.