← לוח פגיעויות

CVE-2024-1488

גבוהה 7.3

תיאור (מקור, אנגלית)

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.

מדדים

CVSS 3.1
7.3 (HIGH) מקור הציון: NVD CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-17/9/2026
CWE
CWE-276

מוצרים מושפעים

fedoraproject: unbound; redhat: codeready linux builder; redhat: codeready linux builder eus; redhat: codeready linux builder eus for power little endian; redhat: codeready linux builder for arm64; redhat: codeready linux builder for arm64 eus; redhat: codeready linux builder for ibm z systems; redhat: codeready linux builder for ibm z systems eus; redhat: enterprise linux; redhat: enterprise linux eus; redhat: enterprise linux for arm 64; redhat: enterprise linux for arm 64 eus; redhat: enterprise linux for ibm z systems; redhat: enterprise linux for ibm z systems eus; redhat: enterprise linux for power little endian

קישורים