Back

MEDIUM

coreDNS: DNS Redirection of Top-Level Domains

Published Mar 3, 2023

Description

A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.

Affected products

Remediation

Red Hat mitigation

- Add a default admission controller to prevent the creation of projects or namespaces that match any TLDs. - Add a warning to the OpenShift documentation that informs users of the potential for abuse in the event any namespaces match a TLD. This warning already exists in the Kubernetes documentation.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 3, 2023
Updated Mar 7, 2025
Reserved Aug 16, 2022
CISA Vulnrichment
Updated Mar 7, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 16, 2022
GHSA-H828-V5PV-33QX