Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24280
HistoryApr 10, 2020 - 12:51 a.m.

Authorization Bypass

2020-04-1000:51:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.023 Low

EPSS

Percentile

89.8%

bind is vulnerable to authorization bypass. The vulnerability exists as it was discovered that, in certain cases, named did not properly perform DNSSEC validation of an NS RRset for zones in the middle of a DNSKEY algorithm rollover. This flaw could cause the validator to incorrectly determine that the zone is insecure and not protected by DNSSEC.

References