First published: Wed Sep 21 2022(Updated: )
A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Openshift | =4.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3262 is a vulnerability found in Openshift that allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.
CVE-2022-3262 affects Openshift by allowing a pod with a DNSPolicy of "ClusterFirst" to incorrectly resolve the hostname based on a service provided.
CVE-2022-3262 has a severity rating of high with a CVSS score of 8.1.
CVE-2022-3262 can be exploited by supplying an incorrect name with the DNS search policy in a pod with a DNSPolicy of "ClusterFirst".
Yes, there are references available for CVE-2022-3262. You can find them at the following links: [Red Hat Service Now](https://redhat.service-now.com/surl.do?n=INC2263871) and [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2128858).