Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3262

Опубликовано: 21 сент. 2022
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.

Отчет

This flaw was found in OpenShift’s DNS resolution when pods use the ClusterFirst DNS policy. The vulnerability exists due to the way how the DNS search path is expanded, if an attacker creates a namespace with a top-level domain (like com or net) and a service with a matching name, pod DNS queries can get redirected inside the cluster instead of going to the real external domain. This can lead to traffic redirection, allowing data interception (loss of confidentiality) or service disruption (loss of availability).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshiftWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-453
https://bugzilla.redhat.com/show_bug.cgi?id=2128858openshift: insecure default DNSPolicy for pods

EPSS

Процентиль: 52%
0.00722
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
почти 4 года назад

A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.

CVSS3: 8.1
github
почти 4 года назад

A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.

EPSS

Процентиль: 52%
0.00722
Низкий

8.1 High

CVSS3