cd=false (DNSSEC) not respected in DNS over HTTPS JSON requests
Low
C
Cloudflare Public Bug Bounty
Submitted None
Team Summary
Official summary from Cloudflare Public Bug Bounty
The value of the `cd` (check disabled) flag was not correctly validated in DNS-over-HTTPS JSON API requests to cloudflare-dns.com. In result, despite explicitly setting the flag value to `0` or `false` (according to the [Cloudflare 1.1.1.1 documentation](https://developers.cloudflare.com/1.1.1.1/encryption/dns-over-https/make-api-requests/dns-json/)) the DNSSEC verification was not enforced for an unaware end user. The fix was released by Cloudflare Engineering team and the flag in question is now validated properly.
Actions:
Reported by
mattipv4
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$250.00
Submitted
Weakness
Business Logic Errors