In PowerDNS Recursor versions up to and including 4.3.1, 4.2.2 and 4.1.16, the ACL restricting access to the internal web server is not properly enforced.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "4.1.16"
},
{
"introduced": "4.2.0"
},
{
"last_affected": "4.2.2"
},
{
"introduced": "4.3.0"
},
{
"last_affected": "4.3.1"
}
]
}