blob: bf2d6f8bd65a4280a990f280b294977c84a17504 [file] [log] [blame]
{
"schema_version": "1.3.1",
"id": "GO-2024-2785",
"modified": "0001-01-01T00:00:00Z",
"published": "0001-01-01T00:00:00Z",
"aliases": [
"CVE-2024-0874",
"GHSA-m9w6-wp3h-vq8g"
],
"summary": "CoreDNS may return invalid cache entries in github.com/coredns/coredns",
"details": "A flaw was found in coredns. This issue could lead to invalid cache entries returning due to incorrectly implemented caching.",
"affected": [
{
"package": {
"name": "github.com/coredns/coredns",
"ecosystem": "Go"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.11.2"
}
]
}
],
"ecosystem_specific": {
"imports": [
{
"path": "github.com/coredns/coredns/plugin/cache",
"symbols": [
"Cache.ServeDNS",
"Cache.exists",
"Cache.getIgnoreTTL",
"ResponseWriter.WriteMsg",
"hash",
"key",
"newPrefetchResponseWriter",
"verifyStaleResponseWriter.WriteMsg"
]
}
]
}
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-m9w6-wp3h-vq8g"
},
{
"type": "FIX",
"url": "https://github.com/coredns/coredns/commit/997c7f953962d47c242273f0e41398fdfb5b0151"
},
{
"type": "FIX",
"url": "https://github.com/coredns/coredns/pull/6354"
},
{
"type": "REPORT",
"url": "https://github.com/coredns/coredns/issues/6186"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:0041"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-0874"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2219234"
}
],
"database_specific": {
"url": "https://pkg.go.dev/vuln/GO-2024-2785",
"review_status": "REVIEWED"
}
}