coreDNS: DNS Redirection of Top-Level Domains
Published Mar 3, 2023
6.1
MEDIUMCVSS 3.1
EPSS 0.39%
Description
A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.
Affected products
- Vendor n/a Product coreDNS Defaultn/a
- Version unknownStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | coreDNS | n/a |
|
- n/a
No data.
Red Hat OpenShift Container Platform 4
openshift4/ose-coredns-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift4/ose-coredns-rhel9 | Not affected | n/a |
github.com/coredns/coredns
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/coredns/coredns | 0 | not fixed |
Remediation
Red Hat mitigation
- Add a default admission controller to prevent the creation of projects or namespaces that match any TLDs. - Add a warning to the OpenShift documentation that informs users of the potential for abuse in the event any namespaces match a TLD. This warning already exists in the Kubernetes documentation.
References (5)
- https://access.redhat.com/security/cve/CVE-2022-2837 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2118543 Issue TrackingMitigationThird Party Advisory
- https://github.com/advisories/GHSA-h828-v5pv-33qx Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2837
- https://www.cve.org/CVERecord?id=CVE-2022-2837
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-2837 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2118543 | Issue TrackingMitigationThird Party Advisory | |
| https://github.com/advisories/GHSA-h828-v5pv-33qx | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-2837 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-2837 |
Change history (0)
No recorded changes yet.