github.com/coredns/coredns is vulnerable to Improper Access Control
53
Medium Risk
The acl plugin allows or denies DNS clients by source address, but its position in the plugin chain lets two response paths sidestep it. Because autopath runs after acl, a query that acl allows is rewritten by autopath into a name in an acl-protected zone that is then resolved without a second acl check. Because cache is ordered before acl, an answer cached for an allowed client is served straight from cache to a client that acl should block. Either way a denied client obtains DNS data the access rules intend to withhold. The fix reorders the directives so acl runs after autopath rewrites and before cache serves answers.
You are affected if you are using a version that falls within the vulnerable range and you rely on the acl plugin to restrict clients while also using the autopath or cache plugin.
github.com/coredns/coredns is vulnerable to Improper Access Control in versions 1.6.4 - 1.14.6.
Upgrade the github.com/coredns/coredns library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.