Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-32473

Опубликовано: 18 апр. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4.7

Описание

Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. In 26.0.0, IPv6 is not disabled on network interfaces, including those belonging to networks where --ipv6=false. An container with an ipvlan or macvlan interface will normally be configured to share an external network link with the host machine. Because of this direct access, (1) Containers may be able to communicate with other hosts on the local network over link-local IPv6 addresses, (2) if router advertisements are being broadcast over the local network, containers may get SLAAC-assigned addresses, and (3) the interface will be a member of IPv6 multicast groups. This means interfaces in IPv4-only networks present an unexpectedly and unnecessarily increased attack surface. The issue is patched in 26.0.2. To completely disable IPv6 in a container, use --sysctl=net.ipv6.conf.all.disable_ipv6=1 in the docker create o...

РелизСтатусПримечание
devel

not-affected

26.1.4+dfsg2-1ubuntu1
esm-apps/bionic

not-affected

20.10.21-0ubuntu1~18.04.3
esm-apps/focal

not-affected

20.10.21-0ubuntu1~20.04.6
esm-apps/jammy

not-affected

20.10.21-0ubuntu1~22.04.7
esm-apps/noble

not-affected

20.10.25+dfsg1-2ubuntu1
esm-infra/xenial

not-affected

18.09.7-0ubuntu1~16.04.9+esm1
focal

not-affected

20.10.21-0ubuntu1~20.04.6
jammy

not-affected

20.10.21-0ubuntu1~22.04.7
mantic

ignored

end of life, was needs-triage
noble

not-affected

20.10.25+dfsg1-2ubuntu1

Показывать по

РелизСтатусПримечание
devel

not-affected

26.1.3-0ubuntu1
esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

not-affected

24.0.7-0ubuntu4
focal

ignored

end of standard support, was needed
jammy

needed

mantic

ignored

end of life, was needs-triage
noble

not-affected

24.0.7-0ubuntu4
oracular

not-affected

26.1.3-0ubuntu1
plucky

not-affected

26.1.3-0ubuntu1

Показывать по

EPSS

Процентиль: 3%
0.00017
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
redhat
около 1 года назад

Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. In 26.0.0, IPv6 is not disabled on network interfaces, including those belonging to networks where `--ipv6=false`. An container with an `ipvlan` or `macvlan` interface will normally be configured to share an external network link with the host machine. Because of this direct access, (1) Containers may be able to communicate with other hosts on the local network over link-local IPv6 addresses, (2) if router advertisements are being broadcast over the local network, containers may get SLAAC-assigned addresses, and (3) the interface will be a member of IPv6 multicast groups. This means interfaces in IPv4-only networks present an unexpectedly and unnecessarily increased attack surface. The issue is patched in 26.0.2. To completely disable IPv6 in a container, use `--sysctl=net.ipv6.conf.all.disable_ipv6=1` in the `docker create` ...

CVSS3: 4.7
nvd
около 1 года назад

Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. In 26.0.0, IPv6 is not disabled on network interfaces, including those belonging to networks where `--ipv6=false`. An container with an `ipvlan` or `macvlan` interface will normally be configured to share an external network link with the host machine. Because of this direct access, (1) Containers may be able to communicate with other hosts on the local network over link-local IPv6 addresses, (2) if router advertisements are being broadcast over the local network, containers may get SLAAC-assigned addresses, and (3) the interface will be a member of IPv6 multicast groups. This means interfaces in IPv4-only networks present an unexpectedly and unnecessarily increased attack surface. The issue is patched in 26.0.2. To completely disable IPv6 in a container, use `--sysctl=net.ipv6.conf.all.disable_ipv6=1` in the `docker create` or

CVSS3: 4.7
debian
около 1 года назад

Moby is an open source container framework that is a key component of ...

CVSS3: 4.7
github
около 1 года назад

IPv6 enabled on IPv4-only network interfaces

CVSS3: 4.7
fstec
около 1 года назад

Уязвимость реализации протокола IPv6 программного средства для создания систем контейнерной изоляции Moby, позволяющая нарушителю получить конфиденциальную информацию

EPSS

Процентиль: 3%
0.00017
Низкий

4.7 Medium

CVSS3

Уязвимость CVE-2024-32473