A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1027 | A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD. |
Github GHSA |
GHSA-h828-v5pv-33qx | coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 07 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-03-07T18:43:09.482Z
Reserved: 2022-08-16T00:00:00.000Z
Link: CVE-2022-2837
Updated: 2024-08-03T00:52:58.994Z
Status : Modified
Published: 2023-03-03T16:15:09.397
Modified: 2025-03-07T19:15:33.503
Link: CVE-2022-2837
OpenCVE Enrichment
No data.
EUVD
Github GHSA