CVE-2023-30464: High severity coredns.io CoreDNS vulnerability
Published Sep 18, 2024
·Updated
CoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses via a birthday attack.
Affected Software
3 affected components
go/github.com/coredns/coredns<=1.10.1
coredns.io CoreDNS<=1.10.1
IBM API Connect<=V10.0.8.0 - V10.0.8.9
Event History
Sep 18, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
Affected Software
Advisory Published
via GitHub·09:30 PM
Jul 7, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-30464?
CVE-2023-30464 has been classified as a critical vulnerability due to its potential for DNS cache poisoning.
2
How do I fix CVE-2023-30464?
To fix CVE-2023-30464, upgrade CoreDNS to version 1.10.2 or later.
3
What software is affected by CVE-2023-30464?
CVE-2023-30464 affects CoreDNS versions up to and including 1.10.1.
4
What kind of attack does CVE-2023-30464 enable?
CVE-2023-30464 enables attackers to perform DNS cache poisoning through a birthday attack.
5
Is there a workaround for CVE-2023-30464 before upgrading?
Currently, there are no known effective workarounds for CVE-2023-30464; upgrading is recommended.