VDB
Sign up
MEDIUM6.1

GHSA-h828-v5pv-33qx

coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints

Details

A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/coredns/coredns
Introduced in: 0

No fixed version published yet for github.com/coredns/coredns (go modules). Pin to a known-safe version or switch to an alternative.

References