Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-28840

Опубликовано: 04 апр. 2023
Источник: nvd
CVSS3: 7.5
CVSS3: 8.7
EPSS Низкий

Описание

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (dockerd), which is developed as moby/moby, is commonly referred to as Docker.

Swarm Mode, which is compiled in and delivered by default in dockerd and is thus present in most major Moby downstreams, is a simple, built-in container orchestrator that is implemented through a combination of SwarmKit and supporting network code.

The overlay network driver is a core feature of Swarm Mode, providing isolated virtual LANs that allow communication between containers and services across the cluster. This driver is an implementation/user of VXLAN, which encapsulates link-layer (Ethernet) frames in UDP datagrams that tag the frame with a VXLAN Network ID (VNI) that identifies the originating overlay network. In addition, the overlay network driver supports an optional, off-by-default encrypte

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:*
Версия от 1.12.0 (включая) до 20.10.24 (исключая)
cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:*
Версия от 23.0.0 (включая) до 23.0.3 (исключая)

EPSS

Процентиль: 61%
0.00425
Низкий

7.5 High

CVSS3

8.7 High

CVSS3

Дефекты

CWE-420
CWE-203

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as moby/moby, is commonly referred to as *Docker*. Swarm Mode, which is compiled in and delivered by default in dockerd and is thus present in most major Moby downstreams, is a simple, built-in container orchestrator that is implemented through a combination of SwarmKit and supporting network code. The overlay network driver is a core feature of Swarm Mode, providing isolated virtual LANs that allow communication between containers and services across the cluster. This driver is an implementation/user of VXLAN, which encapsulates link-layer (Ethernet) frames in UDP datagrams that tag the frame with a VXLAN Network ID (VNI) that identifies the originating overlay network. In addition, the overlay network driver supports an optional, off-by-default encrypt...

CVSS3: 8.7
redhat
больше 2 лет назад

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as moby/moby, is commonly referred to as *Docker*. Swarm Mode, which is compiled in and delivered by default in dockerd and is thus present in most major Moby downstreams, is a simple, built-in container orchestrator that is implemented through a combination of SwarmKit and supporting network code. The overlay network driver is a core feature of Swarm Mode, providing isolated virtual LANs that allow communication between containers and services across the cluster. This driver is an implementation/user of VXLAN, which encapsulates link-layer (Ethernet) frames in UDP datagrams that tag the frame with a VXLAN Network ID (VNI) that identifies the originating overlay network. In addition, the overlay network driver supports an optional, off-by-default encrypt...

CVSS3: 7.5
debian
больше 2 лет назад

Moby is an open source container framework developed by Docker Inc. th ...

CVSS3: 7.5
github
больше 2 лет назад

Docker Swarm encrypted overlay network may be unauthenticated

CVSS3: 7.5
fstec
больше 3 лет назад

Уязвимость режима Swarm Mode демона dockerd программного средства для создания систем контейнерной изоляции Moby и среды выполнения контейнеров Mirantis Container Runtime, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации

EPSS

Процентиль: 61%
0.00425
Низкий

7.5 High

CVSS3

8.7 High

CVSS3

Дефекты

CWE-420
CWE-203