Loading HuntDB...

cd=false (DNSSEC) not respected in DNS over HTTPS JSON requests

Low
C
Cloudflare Public Bug Bounty
Submitted None

Team Summary

Official summary from Cloudflare Public Bug Bounty

The value of the `cd` (check disabled) flag was not correctly validated in DNS-over-HTTPS JSON API requests to cloudflare-dns.com. In result, despite explicitly setting the flag value to `0` or `false` (according to the [Cloudflare 1.1.1.1 documentation](https://developers.cloudflare.com/1.1.1.1/encryption/dns-over-https/make-api-requests/dns-json/)) the DNSSEC verification was not enforced for an unaware end user. The fix was released by Cloudflare Engineering team and the flag in question is now validated properly.

Reported by mattipv4

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$250.00

Submitted

Weakness

Business Logic Errors