CVE-2023-30464

CoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses via a birthday attack.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:coredns.io:coredns:*:*:*:*:*:*:*:*

History

10 Jul 2025, 15:56

Type Values Removed Values Added
First Time Coredns.io
Coredns.io coredns
References () https://gist.github.com/idealeer/e41c7fb3b661d4262d0b6f21e12168ba - () https://gist.github.com/idealeer/e41c7fb3b661d4262d0b6f21e12168ba - Third Party Advisory
CPE cpe:2.3:a:coredns.io:coredns:*:*:*:*:*:*:*:*

19 Sep 2024, 19:35

Type Values Removed Values Added
CWE CWE-290
Summary
  • (es) CoreDNS hasta la versión 1.10.1 permite a los atacantes lograr envenenamiento de caché DNS e inyectar respuestas falsas a través de un ataque de cumpleaños.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

18 Sep 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-18 21:15

Updated : 2025-07-10 15:56


NVD link : CVE-2023-30464

Mitre link : CVE-2023-30464

CVE.ORG link : CVE-2023-30464


JSON object : View

Products Affected

coredns.io

  • coredns
CWE
CWE-290

Authentication Bypass by Spoofing