Database/Container, Kubernetes & orchestration
Docker / moby: Encrypted overlay network traffic can be unencrypted due to missing rules
CVSS 6.8CVE-2023-28841Container, Kubernetes & orchestrationcurated
Impact
Encrypted overlay network traffic can be unencrypted due to missing rules
Who can reach it
Unauthenticated network adjacent to the underlay
What to do
Upgrade moby
References
Related entries
- Docker / moby: Unauthenticated injection of traffic into an encrypted overlay networkCVE-2023-28842 · Docker / mobyMedium
- Docker / moby: Malformed image manifest crashes dockerdCVE-2021-21285 · Docker / mobyMedium
- Docker / moby: NULL pointer dereference in image_history crashes the daemonCVE-2024-36620 · Docker / mobyMedium
- Docker / moby: Race in the buildkit snapshot adapterCVE-2024-36621 · Docker / mobyMedium
- Docker / moby: /var/lib/docker subdirectories world-traversableCVE-2021-41091 · Docker / mobyMedium
- Docker / moby: Companion `docker cp` mount-setup raceCVE-2026-41568 · Docker / mobyMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.