PowerDNS DNSdist
cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*
- >= 1.9.0, <= 1.9.11
- >= 2.0.0, <= 2.0.2
A vulnerability allowing HTML injection into the internal web dashboard of PowerDNS DNSdist has been identified. This issue arises when an attacker sends crafted DNS queries to a DNSdist instance with domain-based dynamic rules enabled, either through the DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI methods. The vulnerability affects PowerDNS DNSdist versions 1.9.0 prior to 1.9.11 and 2.0.0 prior to 2.0.2.
Exploitation of this vulnerability allows for HTML injection, which could be used to manipulate the web dashboard's content or behavior.
Users are advised to upgrade to PowerDNS DNSdist versions 1.9.12 or 2.0.3, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.