CVE-2017-15091

low
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
2.5

Description

An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the server are still allowed even though the API has been configured as read-only via the api-readonly keyword. This missing check allows an attacker with valid API credentials to flush the cache, trigger a zone transfer or send a NOTIFY.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2017-15091

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-201711-30

OS impact

OSVersionStatusFixed in
arch archfixed4.0.5-1
debian debianbookwormfixed4.0.5-1
debian debianbullseyefixed4.0.5-1
debian debianforkyfixed4.0.5-1
debian debiansidfixed4.0.5-1
debian debiantrixiefixed4.0.5-1

References

Verify integrity in audit chain (admin only). AS-IS.