An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 5.4
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade pdns-recursor | Aug 22, 2024 | Jan 29, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 29, 2019 |
| Debian | — | Upgrade pdns-recursor | Feb 14, 2019 | Feb 14, 2019 |
| Freebsd | — | Upgrade powerdns-recursor | Jan 29, 2019 | Jan 22, 2019 |
| Suse | — | Upgrade pdns-recursor | Feb 4, 2022 | Jan 21, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub