An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 5.4
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-pdns-recursor | Aug 22, 2024 | Jan 29, 2019 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Jan 29, 2019 | |
| Debian | debian-upgrade-pdns-recursor | Feb 14, 2019 | Feb 14, 2019 | |
| Freebsd | freebsd-upgrade-package-powerdns-recursor | Jan 29, 2019 | Jan 22, 2019 | |
| Suse | — | suse-upgrade-pdns-recursor | Feb 4, 2022 | Jan 21, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub