MEDIUM6.1
GHSA-h828-v5pv-33qx
coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints
Details
A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/coredns/coredns
Introduced in:
0No fixed version published yet for github.com/coredns/coredns (go modules). Pin to a known-safe version or switch to an alternative.