PT-2023-4601 · Docker+7 · Moby+8

Corhere

·

Published

2023-04-04

·

Updated

2025-10-11

·

CVE-2023-28841

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moby versions prior to 23.0.3 Moby versions prior to 20.10.24 Mirantis Container Runtime versions prior to 20.10.16
Description The issue is related to the encrypted overlay network feature in Moby's Swarm Mode. Encrypted overlay networks function by encapsulating VXLAN datagrams through the use of the IPsec Encapsulating Security Payload protocol in Transport mode. However, on affected platforms, these networks silently transmit unencrypted data, which may appear to be functional but lacks the expected confidentiality and data integrity guarantees. An attacker in a trusted position on the network can read all application traffic moving across the overlay network, resulting in unexpected secrets or user data disclosure. Many database protocols and internal APIs are not protected by a second layer of encryption, so users may rely on Swarm encrypted overlay networks for confidentiality, which is no longer guaranteed due to this vulnerability.
Recommendations Update to Moby release 23.0.3 or later. Update to Moby release 20.10.24 or later. Update to Mirantis Container Runtime version 20.10.16 or later. As a temporary workaround, close the VXLAN port (by default, UDP port 4789) to outgoing traffic at the Internet boundary to prevent unintentionally leaking unencrypted traffic over the Internet. Ensure that the xt u32 kernel module is available on all nodes of the Swarm cluster.

Exploit

Fix

Improper Handling of Exceptional Conditions

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

BDU:2023-05008
CVE-2023-28841
GHSA-232P-VWFF-86MP
GHSA-33PG-M6JH-5237
GHSA-6WRF-MXFJ-PF5P
GHSA-GVM4-2QQG-M333
GHSA-VWM3-CRMR-XFXW
GO-2023-1699
GO-2023-1700
GO-2023-1701
MGASA-2023-0329
OESA-2023-1238
OPENSUSE-SU-2023_3536-1
OPENSUSE-SU-2024:13205-1
OPENSUSE-SU-2025:15589-1
SUSE-SU-2023:3307-1
SUSE-SU-2023:3536-1
SUSE-SU-2025:03540-1
SUSE-SU-2025:03545-1
USN-7474-1

Affected Products

Astra Linux
Debian
Docker
Linuxmint
Mirantis Container Runtime
Moby
Red Os
Suse
Ubuntu