Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34040

Опубликовано: 31 мар. 2026
Источник: redhat
CVSS3: 8.4
EPSS Средний

Описание

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.

A flaw was found in Moby, an open-source container framework. This security vulnerability allows attackers to bypass authorization plugins (AuthZ), which are mechanisms designed to control access and permissions within the container environment. The bypass of these plugins can lead to unauthorized operations and potential compromise of the system's integrity and confidentiality.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-8-rhel8Affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-service-9-rhel9Affected
OpenShift Service Mesh 2openshift-service-mesh/istio-rhel8-operatorNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Affected
Red Hat Ceph Storage 5rhceph-ci/grafanaAffected
Red Hat OpenShift Container Platform 4openshift3/ose-consoleAffected
Red Hat OpenShift Container Platform 4openshift4/ose-agent-installer-api-server-rhel8Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-agent-installer-api-server-rhel9Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-consoleNot affected
Red Hat OpenShift Virtualization 4openshift-virtualization/hostpath-csi-driver-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-807
https://bugzilla.redhat.com/show_bug.cgi?id=2453278Moby: Moby: Authorization bypass vulnerability

EPSS

Процентиль: 95%
0.1014
Средний

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
4 месяца назад

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.

CVSS3: 8.8
nvd
4 месяца назад

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.

CVSS3: 8.8
debian
4 месяца назад

Moby is an open source container framework. Prior to version 29.3.1, a ...

CVSS3: 7.8
redos
2 месяца назад

Уязвимость docker-ce

CVSS3: 8.8
github
4 месяца назад

Moby has AuthZ plugin bypass when provided oversized request bodies

EPSS

Процентиль: 95%
0.1014
Средний

8.4 High

CVSS3