Описание
A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| coredns | itp | package |
Связанные уязвимости
CVSS3: 4.3
redhat
больше 3 лет назад
A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.
CVSS3: 6.1
nvd
почти 3 года назад
A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.
CVSS3: 6.1
github
почти 3 года назад
coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints