CVE-2023-28452: High severity coredns.io CoreDNS vulnerability
An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing denial of service for normal resolution. In an exploit, the attacker could just forge a response targeting the source port of a vulnerable resolver without the need to guess the correct TXID.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28452?
The severity of CVE-2023-28452 is considered high due to its potential for causing denial of service.
How do I fix CVE-2023-28452?
To fix CVE-2023-28452, upgrade CoreDNS to version 1.11.0 or later.
What types of systems are affected by CVE-2023-28452?
CVE-2023-28452 affects CoreDNS versions up to 1.10.1.
What attack vectors are associated with CVE-2023-28452?
CVE-2023-28452 can be exploited by an attacker forging DNS responses targeting the source port.
What impact does CVE-2023-28452 have on DNS resolution?
CVE-2023-28452 causes valid DNS responses to be ignored, resulting in a denial of service for normal DNS resolution.