CVE-2024-1488
CWE-276 — Incorrect Default PermissionsCWE-15CWE-611 — XML External Entity (XXE)6 documents6 sources
Severity
7.3HIGH
EPSS
0.1%
top 70.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 15
Latest updateDec 2
Description
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:HExploitability: 2.5 | Impact: 5.5
Affected Packages3 packages
Also affects: Enterprise Linux 8.0, 9.0, 8.6, 8.8, 9.2, 9.4, 8.2, 8.4
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-35qh-7f6c-rjf7: A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtim↗2024-02-15
CVEList▶
Unbound: unrestricted reconfiguration enabled to anyone that may lead to local privilege escalation↗2024-02-15