Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-28840

Опубликовано: 04 апр. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (dockerd), which is developed as moby/moby, is commonly referred to as Docker. Swarm Mode, which is compiled in and delivered by default in dockerd and is thus present in most major Moby downstreams, is a simple, built-in container orchestrator that is implemented through a combination of SwarmKit and supporting network code. The overlay network driver is a core feature of Swarm Mode, providing isolated virtual LANs that allow communication between containers and services across the cluster. This driver is an implementation/user of VXLAN, which encapsulates link-layer (Ethernet) frames in UDP datagrams that tag the frame with a VXLAN Network ID (VNI) that identifies the originating overlay network. In addition, the overlay network driver supports an optional, off-by-default encrypt...

РелизСтатусПримечание
devel

not-affected

26.1.4+dfsg2-1ubuntu1
esm-apps/bionic

released

20.10.21-0ubuntu1~18.04.3+esm3
esm-apps/focal

released

20.10.21-0ubuntu1~20.04.6+esm2
esm-apps/jammy

released

20.10.21-0ubuntu1~22.04.7+esm2
esm-apps/noble

not-affected

20.10.25+dfsg1-2ubuntu1
esm-infra/xenial

needed

focal

ignored

end of standard support, was needed
jammy

needed

noble

not-affected

20.10.25+dfsg1-2ubuntu1
oracular

not-affected

26.1.4+dfsg2-1ubuntu1

Показывать по

РелизСтатусПримечание
devel

not-affected

26.1.3-0ubuntu1
esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

not-affected

24.0.7-0ubuntu4
focal

ignored

end of standard support, was needed
jammy

needed

noble

not-affected

24.0.7-0ubuntu4
oracular

not-affected

26.1.3-0ubuntu1
plucky

not-affected

26.1.3-0ubuntu1
upstream

needs-triage

Показывать по

EPSS

Процентиль: 61%
0.00425
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.7
redhat
больше 2 лет назад

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as moby/moby, is commonly referred to as *Docker*. Swarm Mode, which is compiled in and delivered by default in dockerd and is thus present in most major Moby downstreams, is a simple, built-in container orchestrator that is implemented through a combination of SwarmKit and supporting network code. The overlay network driver is a core feature of Swarm Mode, providing isolated virtual LANs that allow communication between containers and services across the cluster. This driver is an implementation/user of VXLAN, which encapsulates link-layer (Ethernet) frames in UDP datagrams that tag the frame with a VXLAN Network ID (VNI) that identifies the originating overlay network. In addition, the overlay network driver supports an optional, off-by-default encrypt...

CVSS3: 7.5
nvd
больше 2 лет назад

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (`dockerd`), which is developed as moby/moby, is commonly referred to as *Docker*. Swarm Mode, which is compiled in and delivered by default in dockerd and is thus present in most major Moby downstreams, is a simple, built-in container orchestrator that is implemented through a combination of SwarmKit and supporting network code. The overlay network driver is a core feature of Swarm Mode, providing isolated virtual LANs that allow communication between containers and services across the cluster. This driver is an implementation/user of VXLAN, which encapsulates link-layer (Ethernet) frames in UDP datagrams that tag the frame with a VXLAN Network ID (VNI) that identifies the originating overlay network. In addition, the overlay network driver supports an optional, off-by-default encrypte

CVSS3: 7.5
debian
больше 2 лет назад

Moby is an open source container framework developed by Docker Inc. th ...

CVSS3: 7.5
github
больше 2 лет назад

Docker Swarm encrypted overlay network may be unauthenticated

CVSS3: 7.5
fstec
больше 3 лет назад

Уязвимость режима Swarm Mode демона dockerd программного средства для создания систем контейнерной изоляции Moby и среды выполнения контейнеров Mirantis Container Runtime, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации

EPSS

Процентиль: 61%
0.00425
Низкий

7.5 High

CVSS3