Junglewise Threat Intelligence
CVE-2022-2837: coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints
CVE-2022-2837 · Severity: low · CVSS 3.1 · Published 2023-03-03
Technologies: github.com/coredns/coredns (Go). Vendors: Go.
Executive brief
coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints
Affected products
- Go github.com/coredns/coredns
Related threats
- CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners in p
- CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC request paths
- CoreDNS TSIG authentication bypass in gRPC, QUIC, and DoH transports
- CoreDNS incorrect authorization in transfer plugin ACL selection
- CoreDNS tsig authentication bypass in encrypted transports