CVE-2024-25638
HIGHCVSS 8.9/10EPSS 0.39%
Last modified
CVE-2024-25638 is a high-severity vulnerability rated 8.9/10 on the CVSS scale. dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, allowing an attacker to respond with RRs from different zones. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, allowing an attacker to respond with RRs from different zones. This vulnerability is fixed in 3.6.0.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-25638?
dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, allowing an attacker to respond with RRs from different zones. This vulnerability is fixed in 3.6.0.
How severe is CVE-2024-25638?
CVE-2024-25638 has a CVSS score of 8.9/10 (HIGH severity). The EPSS model estimates a 0.39% probability of exploitation in the next 30 days.
How do I fix CVE-2024-25638?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-25632eLabFTW is an open source electronic lab notebook for resear…8.8
- CVE-2024-25633eLabFTW is an open source electronic lab notebook for resear…5.4
- CVE-2024-25634alf.io is an open source ticket reservation system. Prior to…6.5
- CVE-2024-25635alf.io is an open source ticket reservation system. Prior to…8.8
- CVE-2024-25636Misskey is an open source, decentralized social media platfo…8.8
- CVE-2024-25637October is a self-hosted CMS platform based on the Laravel P…5.4
- CVE-2024-25639Khoj is an application that creates personal AI agents. The …7.5
- CVE-2024-2564A vulnerability was found in PandaXGO PandaX up to 20240310 …7.3
- CVE-2024-25640Iris is a web collaborative platform that helps incident res…5.4
- CVE-2024-25641Cacti provides an operational monitoring and fault managemen…7.2
- CVE-2024-25642Due to improper validation of certificate in SAP Cloud Conne…7.4
- CVE-2024-25643The SAP Fiori app (My Overtime Request) - version 605, does …4.3
Are you affected by CVE-2024-25638?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
