Missing Encryption of Sensitive Data in moby - CVE-2023-28841

 

Missing Encryption of Sensitive Data in moby - CVE-2023-28841

Published: April 5, 2023


Vulnerability identifier: #VU74467
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28841
CWE-ID: CWE-311
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to missing encryption of sensitive data within the overlay network driver. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

moby
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
openSUSE Leap
Ubuntu
openEuler
Fedora
ObjectScale
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
Dell PowerProtect Cyber Recovery
QRadar Suite
IBM Cloud Pak for Multicloud Management
Dell EMC Container Storage Modules
docker.io (Ubuntu package)
golang-github-docker-docker-dev (Ubuntu package)
docker-engine
docker
docker-debuginfo
docker-zsh-completion
docker-bash-completion
docker-fish-completion
moby-engine
app-containers/docker
IBM Cloud Pak System
IBM Cloud Pak for Data Scheduling
IBM Cloud Pak for Business Automation
Dell EMC VxRail Appliance

How to mitigate CVE-2023-28841

Install updates from vendor's website.

moby - addressed in versions 20.10.24, 23.0.3
ObjectScale - update to 1.3.0
QRadar Suite - update to 1.10.21.0
IBM Cloud Pak for Multicloud Management - update to 2.3.8
docker.io (Ubuntu package) - update to Ubuntu Pro
golang-github-docker-docker-dev (Ubuntu package) - update to Ubuntu Pro
Dell EMC Container Storage Modules - update to 1.7.0
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
Cloud Pak for Network Automation - update to 2.4.7
IBM Cloud Pak for Watson AIOps - update to 4.1.1
IBM Cloud Pak for Data Scheduling - update to 4.8.0
DB2 on Cloud Pak for Data - update to 4.8.4
Dell EMC VxRail Appliance - update to 8.0.120
docker-engine - update to 18.09.0-253
Dell PowerProtect Cyber Recovery - update to 19.15.0.1
docker - addressed in versions 20.10.25_ce-98.93.1, 24.0.5_ce-150000.185.1
docker-debuginfo - addressed in versions 20.10.25_ce-98.93.1, 24.0.5_ce-150000.185.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 24.0.0-IF001
docker-zsh-completion - update to 24.0.5_ce-150000.185.1
docker-bash-completion - update to 24.0.5_ce-150000.185.1
docker-fish-completion - update to 24.0.5_ce-150000.185.1
moby-engine - addressed in versions 24.0.5-1.fc37, 24.0.5-1.fc38, 24.0.5-1.fc39
app-containers/docker - update to 25.0.4

External References

Related Security Bulletins