메뉴 건너뛰기

GREATUSER

cve

CVE-2017-15091

관리자 2018.01.25 04:00 조회 수 : 175

An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the server are still allowed even though the API has been configured as read-only via the api-readonly keyword. This missing check allows an attacker with valid API credentials to flush the cache, trigger a zone transfer or send a NOTIFY.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-15091
번호 제목 글쓴이 날짜 조회 수
452 CVE-2015-3257 관리자 2017.08.27 137
451 CVE-2017-2865 관리자 2017.11.09 137
450 CVE-2017-2922 관리자 2017.11.09 137
449 CVE-2018-6029 관리자 2018.01.25 137
448 CVE-2014-7859 관리자 2017.08.27 138
447 CVE-2017-12809 (qemu) 관리자 2017.08.27 139
446 CVE-2017-16565 관리자 2017.11.09 139
445 CVE-2017-2912 관리자 2017.11.09 139
444 CVE-2017-14096 관리자 2018.01.25 139
443 CVE-2017-18045 관리자 2018.01.25 139
442 CVE-2017-15107 관리자 2018.01.25 139
441 CVE-2016-6992 관리자 2016.10.14 140
440 CVE-2017-0095 관리자 2017.03.18 140
439 CVE-2018-6001 관리자 2018.01.25 141
438 CVE-2014-3927 관리자 2017.04.04 142
위로