You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
arnaldo2792
published
GHSA-98h6-q2rr-4h7cFeb 8, 2024
Package
docker-engine
(bottlerocket)
Affected versions
< 1.19.1
Patched versions
1.19.1
Description
A flaw was found in Moby due to an unprotected alternate channel within encrypted overlay networks, which could allow a remote user to bypass security restrictions. By sending a specific requests, arbitrary Ethernet frames could be injected into the encrypted overlay network by encapsulating them in VXLAN datagrams.
A flaw was found in Moby due to an unprotected alternate channel within encrypted overlay networks, which could allow a remote user to bypass security restrictions. By sending a specific requests, arbitrary Ethernet frames could be injected into the encrypted overlay network by encapsulating them in VXLAN datagrams.