PowerDNS DNSdist
cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*
- >= 1.9.0, <= 1.9.11
- >= 2.0.0, <= 2.0.2
A vulnerability exists in PowerDNS DNSdist versions 1.9.0 prior to 1.9.11 and 2.0.0 prior to 2.0.2, where a misconfigured Cross-Origin Resource Sharing (CORS) policy can lead to information disclosure. When the internal webserver is enabled, an attacker may trick an administrator logged into the dashboard into visiting a malicious website, potentially extracting sensitive configuration information from the dashboard.
Exploitation of this vulnerability could result in unauthorized access to sensitive configuration information from the DNSdist dashboard.
Users can upgrade to PowerDNS DNSdist versions 1.9.12 or 2.0.3, or disable the internal webserver.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.