Denial of Service and Information Disclosure Risk in PowerDNS Authoritative Server
CVE-2019-3871
6.5MEDIUM
What is CVE-2019-3871?
A vulnerability exists in the PowerDNS Authoritative Server that allows a remote user to exploit insufficient validation of user data when constructing an HTTP request from a DNS query. This can lead to a Denial of Service (DoS) by forcing the server to connect to an invalid endpoint. Additionally, there is the possibility of information disclosure, where the server could unintentionally connect to an internal endpoint and expose sensitive response data.
Affected Version(s)
pdns 4.1.7
pdns 4.0.7
