A flaw was found in coredns. This issue could lead to invalid cache entries returning due to incorrectly implemented caching.
The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2024:0041 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:4850 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:6009 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:6406 | vendor advisory |
https://access.redhat.com/security/cve/CVE-2024-0874 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2219234 | issue tracking |
https://github.com/coredns/coredns/issues/6186 | |
https://github.com/coredns/coredns/pull/6354 |