In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced. References: https://www.openwall.com/lists/oss-security/2020/07/01/1 https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2020-04.html
Created pdns tracking bugs for this issue: Affects: epel-all [bug 1853010] Affects: fedora-all [bug 1853009]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.