blob: ae4ba0e3170843e0b44a7e1d45d9368ac23f309d [file] [log] [blame]
id: GO-2024-3134
modules:
- module: github.com/coredns/coredns
versions:
- fixed: 1.11.0
vulnerable_at: 1.10.1
packages:
- package: github.com/coredns/coredns/plugin/pkg/proxy
symbols:
- Proxy.Connect
summary: CoreDNS Cache Poisoning via a birthday attack in github.com/coredns/coredns
description: |-
CoreDNS enables attackers to achieve DNS cache poisoning and inject fake
responses via a birthday attack.
cves:
- CVE-2023-30464
ghsas:
- GHSA-h92q-fgpp-qhrq
references:
- advisory: https://github.com/advisories/GHSA-h92q-fgpp-qhrq
- fix: https://github.com/coredns/coredns/commit/604a902e2c7e0317aecaa3666124079c75a31573
- web: https://gist.github.com/idealeer/e41c7fb3b661d4262d0b6f21e12168ba
source:
id: GHSA-h92q-fgpp-qhrq
created: 2024-09-26T13:39:52.381917-04:00
review_status: REVIEWED