← All CVEs

CVE-2019-3871

medium · 6.5

A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user when building a HTTP request from a DNS query in the HTTP Connector of the Remote backend, allowing a remote user to cause a denial of service by making the server connect to an invalid endpoint, or possibly information disclosure by making the server connect to an internal endpoint and somehow extracting meaningful information about the response

6.5
CVSS
12.6%
EPSS (exploit prob.)
96th
EPSS percentile
2019-03-21
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
powerdnsauthoritative_server< 4.0.7
powerdnsauthoritative_server>= 4.1.0, < 4.1.7
fedoraprojectfedora28
fedoraprojectfedora29

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-3871