hickory-net is vulnerable to Improper Verification of Cryptographic Signature
53
Medium Risk
DNSSEC validation of positive responses only requires that some valid RRset be present in the answer section, without checking that the RRset actually answers the query. A response that carries a validly signed but unrelated RRset is accepted as a positive answer. When no records match the query, the response should instead be validated as a no-data response. The fix verifies that the validated RRset is responsive to the query.
You are affected if you are using a version that falls within the vulnerable range and you have DNSSEC validation enabled
hickory-net is vulnerable to Improper Verification of Cryptographic Signature in versions 0.26.0 - 0.26.1.
Upgrade the hickory-net library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.