Описание
A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.
Отчет
This flaw was found in OpenShift’s DNS resolution when pods use the ClusterFirst DNS policy. The vulnerability exists due to the way how the DNS search path is expanded, if an attacker creates a namespace with a top-level domain (like com or net) and a service with a matching name, pod DNS queries can get redirected inside the cluster instead of going to the real external domain. This can lead to traffic redirection, allowing data interception (loss of confidentiality) or service disruption (loss of availability).
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
8.1 High
CVSS3
Связанные уязвимости
A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.
A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.
EPSS
8.1 High
CVSS3