CVE-2022-2835: coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints
A flaw was found in coreDNS. This flaw allows a malicious user to reroute internal calls to some internal services that were accessed by the FQDN in a format of ..svc.
References
Detect and mitigate CVE-2022-2835 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →