MEDIUM4.4
GHSA-ch7v-37xg-75ph
coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints
Details
A flaw was found in coreDNS. This flaw allows a malicious user to reroute internal calls to some internal services that were accessed by the FQDN in a format of <service>.<namespace>.svc.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/coredns/coredns
Introduced in:
0No fixed version published yet for github.com/coredns/coredns (go modules). Pin to a known-safe version or switch to an alternative.