CVE-2017-7557: CSRF
Published Aug 22, 2017
·Updated
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
Affected Software
1 affected component
PowerDNS DNSDist=1.1.0
Remediation
Event History
Aug 22, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7557?
CVE-2017-7557 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2017-7557?
To fix CVE-2017-7557, upgrade to a version of dnsdist later than 1.1.0 that addresses this vulnerability.
3
What type of attack does CVE-2017-7557 allow for?
CVE-2017-7557 can potentially allow for Cross-Site Request Forgery (CSRF) attacks.
4
Which versions of dnsdist are affected by CVE-2017-7557?
CVE-2017-7557 specifically affects dnsdist version 1.1.0.
5
Is there any workaround for CVE-2017-7557?
Currently, the recommended action for CVE-2017-7557 is to upgrade to a patched version rather than relying on workarounds.