<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:coredns:coredns:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3acorednscoredns/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 07 Sep 2026 13:34:21 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3acorednscoredns/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CoreDNS DNS Record Manipulation Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-09-coredns-manipulation/</link><pubDate>Mon, 07 Sep 2026 13:34:21 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-coredns-manipulation/</guid><description>A vulnerability in CoreDNS allows a remote, unauthenticated attacker to manipulate DNS records, potentially enabling traffic redirection or DNS cache poisoning.</description><content:encoded><![CDATA[<p>CoreDNS, a flexible, extensible DNS server widely used in Kubernetes environments, contains a vulnerability (CVE-2024-45337) that allows remote, unauthenticated attackers to manipulate DNS records. This flaw impacts the integrity of DNS resolutions performed by the server. By exploiting this weakness, an attacker could potentially inject malicious DNS responses, leading to traffic redirection to attacker-controlled infrastructure or performing DNS cache poisoning attacks. Organizations relying on CoreDNS for internal name resolution or as a cluster-internal DNS provider should prioritize investigating their deployment configurations and monitoring for anomalous DNS traffic patterns that deviate from expected internal service resolution behavior.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an attacker to compromise the integrity of DNS lookups within the affected environment. This could lead to the redirection of service traffic, enabling interception of sensitive data, service disruption, or the facilitation of further exploitation steps against applications relying on DNS for connectivity. The scope of impact is highly dependent on the architecture of the DNS infrastructure, affecting any environment that utilizes CoreDNS for recursive or authoritative resolution.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification and patching of all CoreDNS deployments within the environment, ensuring versions susceptible to CVE-2024-45337 are upgraded to the latest secure release. Because this vulnerability involves manipulation of DNS records, detection engineering teams should implement monitoring for unexpected outbound DNS requests or discrepancies in resolution patterns from core network infrastructure.</p>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>dns</category><category>vulnerability</category><category>coredns</category></item></channel></rss>