Back

HIGH

openshift: insecure default DNSPolicy for pods

Published Dec 8, 2022

Description

A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.

Affected products

Remediation

Red Hat statement

This flaw was found in OpenShift’s DNS resolution when pods use the ClusterFirst DNS policy. The vulnerability exists due to the way how the DNS search path is expanded, if an attacker creates a namespace with a top-level domain (like com or net) and a service with a matching name, pod DNS queries can get redirected inside the cluster instead of going to the real external domain. This can lead to traffic redirection, allowing data interception (loss of confidentiality) or service disruption (loss of availability).

Metrics

Weaknesses (2)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 8, 2022
Updated Apr 23, 2025
Reserved Sep 21, 2022
CISA Vulnrichment
Updated Apr 23, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 21, 2022