hickory-server is vulnerable to Improper Verification of Cryptographic Signature
55
Medium Risk
When the validating recursive resolver and forwarder assemble NXDOMAIN or NODATA responses, they do not check whether the SOA record in the authority section passed DNSSEC validation. A forged SOA record can therefore be returned to clients in a response with the authenticated-data bit set. The impact affects clients that rely on the server for validation and use the SOA contents. The fix checks the SOA validation status before setting AD.
You are affected if you are using a version that falls within the vulnerable range and you run the validating recursive resolver or forwarder and clients trust its AD bit
hickory-server is vulnerable to Improper Verification of Cryptographic Signature in versions 0.25.0 - 0.26.1.
Upgrade the hickory-server library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.