Описание
A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| coredns | itp | package |
Связанные уязвимости
CVSS3: 4.3
redhat
около 4 лет назад
A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.
CVSS3: 6.1
nvd
больше 3 лет назад
A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.
CVSS3: 6.1
github
больше 3 лет назад
coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints