Vulnerability Name: | CVE-2022-27227 (CCN-222599) | ||||||||||||
Assigned: | 2022-03-25 | ||||||||||||
Published: | 2022-03-25 | ||||||||||||
Updated: | 2022-07-30 | ||||||||||||
Summary: | In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an IXFR end condition causes incomplete zone transfers to be handled as successful transfers. | ||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
| ||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-27227 Source: MLIST Type: Mailing List, Patch, Third Party Advisory [oss-security] 20220325 Security Advisory 2022-01 for PowerDNS Authoritative Server 4.4.2, 4.5.3, 4.6.0 and PowerDNS Recursor 4.4.7, 4.5.7, 4.6.0 Source: MISC Type: Vendor Advisory https://doc.powerdns.com/authoritative/security-advisories/index.html Source: CONFIRM Type: Vendor Advisory https://doc.powerdns.com/authoritative/security-advisories/powerdns-advisory-2022-01.html Source: MISC Type: Vendor Advisory https://docs.powerdns.com/recursor/security-advisories/index.html Source: CONFIRM Type: Vendor Advisory https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2022-01.html Source: XF Type: UNKNOWN powerdns-cve202227227-sec-bypass(222599) Source: FEDORA Type: Mailing List, Patch, Third Party Advisory FEDORA-2022-8367cefdea Source: FEDORA Type: Mailing List, Patch, Third Party Advisory FEDORA-2022-6e19acf414 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2022-ccfd5d1045 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2022-1df2a841e4 Source: CCN Type: Seclists.org Web site Security Advisory 2022-01 for PowerDNS Authoritative Server 4.4.2, 4.5.3, 4.6.0 and PowerDNS Recursor 4.4.7, 4.5.7, 4.6.0 Source: CCN Type: oss-sec Mailing List, Fri, 25 Mar 2022 13:36:28 +0100 (CET) Security Advisory 2022-01 for PowerDNS Authoritative Server 4.4.2, 4.5.3, 4.6.0 and PowerDNS Recursor 4.4.7, 4.5.7, 4.6.0 Source: CCN Type: PowerDNS Web site PowerDNS | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||||||
BACK |