In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://www.openwall.com/lists/oss-security/2020/07/01/1 | mailing list release notes third party advisory |
https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-04.html | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00043.html | third party advisory vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00044.html | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00042.html | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7TUNCUZNASYSTVD35QGFAI6XO2BFMQ2F/ | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00036.html | vendor advisory |