CVE-2022-2837: Medium severity coredns.io CoreDNS vulnerability
A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.
Other sources
It is possible for a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects/namespaces that match the TLD.
References - https://docs.openshift.com/container-platform/4.10/architecture/admission-plug-ins.html#admission-plug-ins-defaultadmission-plug-ins - https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/#namespaces-and-dns - https://cwe.mitre.org/data/definitions/923.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2837?
CVE-2022-2837 has been assigned a high severity rating due to the potential for traffic redirection by malicious users.
How do I fix CVE-2022-2837?
To fix CVE-2022-2837, you should upgrade to a patched version of CoreDNS that addresses the vulnerability.
What type of attack does CVE-2022-2837 enable?
CVE-2022-2837 enables attackers to redirect traffic intended for external top-level domains to a controlled pod.
Which software is affected by CVE-2022-2837?
CVE-2022-2837 affects CoreDNS, specifically versions prior to the security patches.
What are the implications of CVE-2022-2837 for DNS security?
CVE-2022-2837 compromises DNS security by allowing malicious users to intercept and redirect legitimate traffic.