Description
ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected products
- PowerDNS / Recursor5.2.0 – 5.2.11
- PowerDNS / Recursor5.3.0 – 5.3.8
- PowerDNS / Recursor5.4.0 – 5.4.3