
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-12244 affects PowerDNS Recursor versions 4.1.0 through 4.3.0. The vulnerability was discovered by Matt Nordhoff and publicly disclosed on May 19, 2020. The issue impacts the DNSSEC validation functionality in PowerDNS Recursor, a non-authoritative/recursing DNS server (PowerDNS Advisory).
The vulnerability exists in the SyncRes::processAnswer functionality where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated. This vulnerability has been assigned a medium severity rating (PowerDNS Advisory, OSS Security).
The vulnerability allows an attacker in position of man-in-the-middle to send a NXDOMAIN answer for a name that does exist, effectively bypassing DNSSEC validation (PowerDNS Advisory).
The vulnerability requires an attacker to be in a man-in-the-middle position to exploit. No public exploits were reported at the time of disclosure (PowerDNS Advisory).
The issue was fixed in PowerDNS Recursor versions 4.3.1, 4.2.2, and 4.1.16. Users are advised to upgrade to these or newer versions. No workarounds are available for this vulnerability (OSS Security, PowerDNS Advisory).
Multiple Linux distributions released security updates to address this vulnerability, including Debian with DSA-4691-1, Fedora with updates for versions 31 and 32, and OpenSUSE with update SU-2020:0698-1 (Debian Security, Fedora Update, OpenSUSE Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."