Database/Container, Kubernetes & orchestration
Docker / moby: DNS requests from an internal network can be forwarded to external resolvers, leaking data out
CVSS 5.9CVE-2024-29018Container, Kubernetes & orchestrationcurated
Impact
DNS requests from an internal network can be forwarded to external resolvers, leaking data out of an isolated network
Who can reach it
Any tenant workload on an "internal" Docker network
What to do
Upgrade moby
References
Related entries
- Docker / moby: Default OCI spec does not mask /proc/acpi, so a container can change host hardware stateCVE-2018-10892 · Docker / mobyMedium
- Docker / moby: Supplementary groups not set up properlyCVE-2022-36109 · Docker / mobyMedium
- Docker / moby: On firewalld reload, published container ports become reachable from outside despite the intendedCVE-2025-54388 · Docker / mobyMedium
- Docker / moby: IPv6 not disabled on interfaces where it should beCVE-2024-32473 · Docker / mobyMedium
- Docker / moby: Related firewalld handling defect affecting Moby port exposureCVE-2025-54410 · Docker / mobyLow
- Docker / moby: `docker cp` into a crafted container changes Unix permissions of existing host filesCVE-2021-41089 · Docker / mobyLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.