Coredns: cd bit response is cached and served later
Published Apr 25, 2024
6.9
MEDIUMCVSS 4.0
EPSS 0.76%
Description
A flaw was found in coredns. This issue could lead to invalid cache entries returning due to incorrectly implemented caching.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | affected |
|
No data.
No data.
Red Hat OpenShift Container Platform 4.13
openshift4/ose-coredns:v4.13.0-202408260940.p0.ge70f097.assembly.stream.el8
Fixed · RHSA-2024:6009
Red Hat OpenShift Container Platform 4.14
openshift4/ose-coredns:v4.14.0-202408260910.p0.gfdd6037.assembly.stream.el8
Fixed · RHSA-2024:6406
Red Hat OpenShift Container Platform 4.15
openshift4/ose-coredns-rhel9:v4.15.0-202407230407.p0.g1326282.assembly.stream.el9
Fixed · RHSA-2024:4850
Red Hat OpenShift Container Platform 4.16
openshift4/ose-coredns-rhel9:v4.16.0-202406131906.p0.g04d84f7.assembly.stream.el9
Fixed · RHSA-2024:0041
Logging Subsystem for Red Hat OpenShift
openshift-logging/logging-loki-rhel9
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/lighthouse-agent-rhel9
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4.13 | openshift4/ose-coredns:v4.13.0-202408260940.p0.ge70f097.assembly.stream.el8 | Fixed | RHSA-2024:6009 |
| Red Hat OpenShift Container Platform 4.14 | openshift4/ose-coredns:v4.14.0-202408260910.p0.gfdd6037.assembly.stream.el8 | Fixed | RHSA-2024:6406 |
| Red Hat OpenShift Container Platform 4.15 | openshift4/ose-coredns-rhel9:v4.15.0-202407230407.p0.g1326282.assembly.stream.el9 | Fixed | RHSA-2024:4850 |
| Red Hat OpenShift Container Platform 4.16 | openshift4/ose-coredns-rhel9:v4.16.0-202406131906.p0.g04d84f7.assembly.stream.el9 | Fixed | RHSA-2024:0041 |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/logging-loki-rhel9 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/lighthouse-agent-rhel9 | Will not fix | n/a |
github.com/coredns/coredns
Go
Introduced 0 Fixed 1.11.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/coredns/coredns | 0 | 1.11.2 |
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jul 13, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (5 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.76% (0.00760) | 53.71th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.76% (0.00760) | 50.29th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.43% (0.00432) | 60.53th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 15.00th | v3 (v2023.03.01) |
| Apr 26, 2024 | 0.04% (0.00045) | 14.14th | v3 (v2023.03.01) |
References (12)
- https://access.redhat.com/errata/RHSA-2024:0041 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:4850 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:6009 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:6406 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-0874 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2219234 issue-trackingx_refsource_REDHATIssue Tracking
- https://github.com/advisories/GHSA-m9w6-wp3h-vq8g Advisory
- https://github.com/coredns/coredns/commit/997c7f953962d47c242273f0e41398fdfb5b0151
- https://github.com/coredns/coredns/issues/6186
- https://github.com/coredns/coredns/pull/6354
- https://nvd.nist.gov/vuln/detail/CVE-2024-0874
- https://www.cve.org/CVERecord?id=CVE-2024-0874
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2024:0041 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2024:4850 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2024:6009 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2024:6406 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2024-0874 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2219234 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://github.com/advisories/GHSA-m9w6-wp3h-vq8g | Advisory | |
| https://github.com/coredns/coredns/commit/997c7f953962d47c242273f0e41398fdfb5b0151 | ||
| https://github.com/coredns/coredns/issues/6186 | ||
| https://github.com/coredns/coredns/pull/6354 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2024-0874 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-0874 |
Change history (0)
No recorded changes yet.