REDHAT-BUG-2445244: High severity CoreDNS CoreDNS vulnerability
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the rewrite plugin, resulting in a Time-of-Check Time-of-Use (TOCTOU) flaw. This issue has been patched in version 1.14.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CoreDNSto a version that resolves this vulnerability.Fixed in 1.14.2
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2445244?
The severity of REDHAT-BUG-2445244 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2445244?
To fix REDHAT-BUG-2445244, upgrade CoreDNS to version 1.14.2 or later.
What vulnerability exists in CoreDNS related to REDHAT-BUG-2445244?
REDHAT-BUG-2445244 describes a logical vulnerability that allows DNS access control to be bypassed due to the execution order of plugins.
Which plugins are affected by the vulnerability in REDHAT-BUG-2445244?
The acl security plugin and the rewrite plugin are directly affected by the vulnerability identified in REDHAT-BUG-2445244.
What impact could REDHAT-BUG-2445244 have on my network?
If exploited, REDHAT-BUG-2445244 could allow unauthorized DNS queries and control over DNS access, compromising network security.