PowerDNS DNSdist
cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*
- >= 1.9.0, <= 1.9.11
- >= 2.0.0, <= 2.0.2
An ACL bypass vulnerability has been identified in PowerDNS DNSdist versions 1.9.0 through 1.9.11 and 2.0.0 through 2.0.2. When the 'early_acl_drop' option is disabled on a DNS over HTTPS frontend using the nghttp2 provider, the ACL check is bypassed. This allows all clients to send DoH queries, regardless of the configured ACL. The vulnerability can be exploited by sending crafted DoH queries, taking advantage of the skipped ACL checks.
Exploiting this vulnerability can lead to unauthorized clients bypassing ACL restrictions and sending DoH queries, potentially causing disruptions or unauthorized access to services that rely on these ACLs.
Users can upgrade to PowerDNS DNSdist versions 1.9.12 or 2.0.3, where this vulnerability has been patched. Alternatively, the 'early_acl_drop' option can be kept enabled, which is the default setting.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.