VDB
BDU%3A2025-00341
BDU%3A2025-00341
PUBLISHED
CVSS 5.300000190734863 MEDIUM
Уязвимость DNS сервера coredns, связанная с раскрытием информации посредством кэширования, позволяющая нарушителю проводить спуфинг-атаки
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ООО «Ред Софт», Red Hat Inc., Сообщество свободного программного обеспечения, IBM Corp. | РЕД ОС (запись в едином реестре российских программ №3751), Red Hat Advanced Cluster Management for Kubernetes, Red Hat OpenShift Container Platform, coredns, Storage Protect Server | |
| Red Hat | Red Hat OpenShift Container Platform 4.15 | v4.15.0-202407230407.p0.g1326282.assembly.stream.el9 |
| Red Hat | Red Hat OpenShift Container Platform 4.16 | v4.16.0-202406131906.p0.g04d84f7.assembly.stream.el9 |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | v4.14.0-202408260910.p0.gfdd6037.assembly.stream.el8 |
| 0 | ||
| Red Hat | Logging Subsystem for Red Hat OpenShift | |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | |
| Red Hat | Red Hat OpenShift Container Platform 4.13 | v4.13.0-202408260940.p0.ge70f097.assembly.stream.el8 |
Timeline
- Feb 18, 2024 PoC Published
- Apr 25, 2024 CVE Published
- Jan 16, 2025 CVE Updated
- Jan 20, 2025 PoC Published
- Mar 20, 2025 PoC Published
- Jun 4, 2026 Distribution Patch
- Jun 4, 2026 Distribution Patch
- Jun 4, 2026 Distribution Patch
- Jun 4, 2026 Distribution Patch
- Jun 4, 2026 Security Advisory
- Jun 4, 2026 Security Advisory
- Jun 4, 2026 Security Advisory
References
- https://redos.red-soft.ru/support/secure/ url
- https://github.com/advisories/GHSA-m9w6-wp3h-vq8g url
- https://github.com/coredns/coredns/issues/6186 url
- https://github.com/coredns/coredns/pull/6354 url
- https://www.ibm.com/support/pages/security-bulletin-ibm-storage-protect-server-susceptible-multiple-authentication-related-vulnerabilities-due-coredns-cve-2022-2837-cve-2022-2835-cve-2024-0874 url
- https://access.redhat.com/security/cve/cve-2024-0874 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory
- RHSA-2024:0041 vendor-advisory
- RHSA-2024:4850 vendor-advisory
- RHSA-2024:6009 vendor-advisory
- RHSA-2024:6406 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-0874 vdb
- RHBZ#2219234 issue