Configuration Injection in Unbound Due to Community Script Vulnerability
CVE-2019-25031
5.9MEDIUM
What is CVE-2019-25031?
A configuration injection vulnerability exists in the community-contributed script 'create_unbound_ad_servers.sh' in Unbound, prior to version 1.9.5. This vulnerability can be exploited through a successful man-in-the-middle attack on a cleartext HTTP session, potentially allowing an attacker to alter configurations unknowingly. It's important to note that the script is not part of the official Unbound installation and thus, the vendor does not classify this as a vulnerability within Unbound software itself.
