PT-2023-4601 · Docker+7 · Moby+8

Corhere

·

Publicado

2023-04-04

·

Atualizado

2025-10-11

·

CVE-2023-28841

CVSS v3.1

6.8

Média

VetorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moby versions prior to 23.0.3 Moby versions prior to 20.10.24 Mirantis Container Runtime versions prior to 20.10.16
Description The issue is related to the encrypted overlay network feature in Moby's Swarm Mode. Encrypted overlay networks function by encapsulating VXLAN datagrams through the use of the IPsec Encapsulating Security Payload protocol in Transport mode. However, on affected platforms, these networks silently transmit unencrypted data, which may appear to be functional but lacks the expected confidentiality and data integrity guarantees. An attacker in a trusted position on the network can read all application traffic moving across the overlay network, resulting in unexpected secrets or user data disclosure. Many database protocols and internal APIs are not protected by a second layer of encryption, so users may rely on Swarm encrypted overlay networks for confidentiality, which is no longer guaranteed due to this vulnerability.
Recommendations Update to Moby release 23.0.3 or later. Update to Moby release 20.10.24 or later. Update to Mirantis Container Runtime version 20.10.16 or later. As a temporary workaround, close the VXLAN port (by default, UDP port 4789) to outgoing traffic at the Internet boundary to prevent unintentionally leaking unencrypted traffic over the Internet. Ensure that the xt u32 kernel module is available on all nodes of the Swarm cluster.

Exploit

Correção

Improper Handling of Exceptional Conditions

Missing Encryption of Sensitive Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05008
CVE-2023-28841
GHSA-232P-VWFF-86MP
GHSA-33PG-M6JH-5237
GHSA-6WRF-MXFJ-PF5P
GHSA-GVM4-2QQG-M333
GHSA-VWM3-CRMR-XFXW
GO-2023-1699
GO-2023-1700
GO-2023-1701
MGASA-2023-0329
OESA-2023-1238
OPENSUSE-SU-2023_3536-1
OPENSUSE-SU-2024:13205-1
OPENSUSE-SU-2025:15589-1
SUSE-SU-2023:3307-1
SUSE-SU-2023:3536-1
SUSE-SU-2025:03540-1
SUSE-SU-2025:03545-1
USN-7474-1

Produtos afetados

Astra Linux
Debian
Docker
Linuxmint
Mirantis Container Runtime
Moby
Red Os
Suse
Ubuntu