Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-29018

Опубликовано: 20 мар. 2024
Источник: nvd
CVSS3: 5.9
CVSS3: 7.5
EPSS Низкий

Описание

Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. Moby's networking implementation allows for many networks, each with their own IP address range and gateway, to be defined. This feature is frequently referred to as custom networks, as each network can have a different driver, set of parameters and thus behaviors. When creating a network, the --internal flag is used to designate a network as internal. The internal attribute in a docker-compose.yml file may also be used to mark a network internal, and other API clients may specify the internal parameter as well.

When containers with networking are created, they are assigned unique network interfaces and IP addresses. The host serves as a router for non-internal networks, with a gateway IP that provides SNAT/DNAT to/from container IPs.

Containers on an internal network may communicate between each other, but are preclu

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:*
Версия до 23.0.11 (исключая)
cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:*
Версия от 24.0.0 (включая) до 25.0.5 (исключая)
cpe:2.3:a:mobyproject:moby:26.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:mobyproject:moby:26.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:mobyproject:moby:26.0.0:rc3:*:*:*:*:*:*

EPSS

Процентиль: 35%
0.00143
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-669
CWE-669

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 1 года назад

Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. Moby's networking implementation allows for many networks, each with their own IP address range and gateway, to be defined. This feature is frequently referred to as custom networks, as each network can have a different driver, set of parameters and thus behaviors. When creating a network, the `--internal` flag is used to designate a network as _internal_. The `internal` attribute in a docker-compose.yml file may also be used to mark a network _internal_, and other API clients may specify the `internal` parameter as well. When containers with networking are created, they are assigned unique network interfaces and IP addresses. The host serves as a router for non-internal networks, with a gateway IP that provides SNAT/DNAT to/from container IPs. Containers on an internal network may communicate between each other, but are precl...

CVSS3: 5.9
redhat
больше 1 года назад

Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. Moby's networking implementation allows for many networks, each with their own IP address range and gateway, to be defined. This feature is frequently referred to as custom networks, as each network can have a different driver, set of parameters and thus behaviors. When creating a network, the `--internal` flag is used to designate a network as _internal_. The `internal` attribute in a docker-compose.yml file may also be used to mark a network _internal_, and other API clients may specify the `internal` parameter as well. When containers with networking are created, they are assigned unique network interfaces and IP addresses. The host serves as a router for non-internal networks, with a gateway IP that provides SNAT/DNAT to/from container IPs. Containers on an internal network may communicate between each other, but are precl...

CVSS3: 7.5
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 5.9
debian
больше 1 года назад

Moby is an open source container framework that is a key component of ...

suse-cvrf
3 месяца назад

Security update for docker

EPSS

Процентиль: 35%
0.00143
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-669
CWE-669