CVE-2022-2835: Medium severity coredns.io CoreDNS vulnerability
A flaw was found in coreDNS. This flaw allows a malicious user to reroute internal calls to some internal services that were accessed by the FQDN in a format of <service>.<namespace>.svc.
Other sources
A flaw was found in coreDNS. This flaw allows a malicious user to reroute internal calls to some internal services that were accessed by the FQDN in a format of service.namespace.svc.
— IBM
It was found that a malicious user could reroute internal calls to some internal services that were being accessed by the FQDN in a format of <service>.<namespace>.svc
References - https://cwe.mitre.org/data/definitions/923.html - https://docs.openshift.com/container-platform/4.10/architecture/admission-plug-ins.html#admission-plug-ins-defaultadmission-plug-ins
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2835?
CVE-2022-2835 is classified as a medium severity vulnerability.
How does CVE-2022-2835 exploit CoreDNS?
CVE-2022-2835 allows a malicious user to reroute internal service calls accessed by FQDN in the format <service>.<namespace>.svc.
Which versions of CoreDNS are affected by CVE-2022-2835?
CVE-2022-2835 affects all versions of CoreDNS prior to the patch.
How can I mitigate the risk of CVE-2022-2835?
Mitigation for CVE-2022-2835 can be achieved by upgrading to a patched version of CoreDNS.
What impact does CVE-2022-2835 have on Kubernetes services?
CVE-2022-2835 potentially exposes Kubernetes internal services to unauthorized access through service rerouting.