{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acorednscoredns/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:coredns:coredns:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2024-45337"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CoreDNS"],"_cs_severities":["medium"],"_cs_tags":["dns","vulnerability","coredns"],"_cs_type":"advisory","_cs_vendors":["CNCF"],"content_html":"\u003cp\u003eCoreDNS, a flexible, extensible DNS server widely used in Kubernetes environments, contains a vulnerability (CVE-2024-45337) that allows remote, unauthenticated attackers to manipulate DNS records. This flaw impacts the integrity of DNS resolutions performed by the server. By exploiting this weakness, an attacker could potentially inject malicious DNS responses, leading to traffic redirection to attacker-controlled infrastructure or performing DNS cache poisoning attacks. Organizations relying on CoreDNS for internal name resolution or as a cluster-internal DNS provider should prioritize investigating their deployment configurations and monitoring for anomalous DNS traffic patterns that deviate from expected internal service resolution behavior.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker to compromise the integrity of DNS lookups within the affected environment. This could lead to the redirection of service traffic, enabling interception of sensitive data, service disruption, or the facilitation of further exploitation steps against applications relying on DNS for connectivity. The scope of impact is highly dependent on the architecture of the DNS infrastructure, affecting any environment that utilizes CoreDNS for recursive or authoritative resolution.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and patching of all CoreDNS deployments within the environment, ensuring versions susceptible to CVE-2024-45337 are upgraded to the latest secure release. Because this vulnerability involves manipulation of DNS records, detection engineering teams should implement monitoring for unexpected outbound DNS requests or discrepancies in resolution patterns from core network infrastructure.\u003c/p\u003e\n","date_modified":"2026-09-07T13:34:21Z","date_published":"2026-09-07T13:34:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-coredns-manipulation/","summary":"A vulnerability in CoreDNS allows a remote, unauthenticated attacker to manipulate DNS records, potentially enabling traffic redirection or DNS cache poisoning.","title":"CoreDNS DNS Record Manipulation Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-coredns-manipulation/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:coredns:coredns:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}