MEDIUM6.5
GHSA-crjg-w57m-rqqf
DNSJava vulnerable to KeyTrap - Denial-of-Service Algorithmic Complexity Attacks
Quick fix
GHSA-crjg-w57m-rqqf — dnsjava:dnsjava: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.6.0</version> for dnsjava:dnsjavaDetails
### Impact Users using the `ValidatingResolver` for DNSSEC validation can run into CPU exhaustion with specially crafted DNSSEC-signed zones.
### Patches Users should upgrade to dnsjava v3.6.0
### Workarounds Although not recommended, only using a non-validating resolver, will remove the vulnerability.
### References https://www.athene-center.de/en/keytrap
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/dnsjava:dnsjava
Introduced in:
3.5.0Fixed in: 3.6.0Fix
# pom.xml: bump <version>3.6.0</version> for dnsjava:dnsjavaMaven/org.jitsi:dnssecjava
Introduced in:
0No fixed version published yet for org.jitsi:dnssecjava (maven). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/dnsjava/dnsjava/security/advisories/GHSA-crjg-w57m-rqqf[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-50387[ADVISORY]
- https://github.com/dnsjava/dnsjava/commit/07ac36a11578cc1bce0cd8ddf2fe568f062aee78[WEB]
- https://github.com/dnsjava/dnsjava/commit/3ddc45ce8cdb5c2274e10b7401416f497694e1cf[WEB]
- https://github.com/advisories/GHSA-8459-gg55-8qjj[ADVISORY]
- https://github.com/dnsjava/dnsjava[PACKAGE]