Missing Encryption of Sensitive Data in moby - CVE-2023-28841
Published: April 5, 2023
Vulnerability identifier: #VU74467
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28841
CWE-ID: CWE-311
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to missing encryption of sensitive data within the overlay network driver. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
moby
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
openSUSE Leap
Ubuntu
openEuler
Fedora
ObjectScale
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
Dell PowerProtect Cyber Recovery
QRadar Suite
IBM Cloud Pak for Multicloud Management
Dell EMC Container Storage Modules
docker.io (Ubuntu package)
golang-github-docker-docker-dev (Ubuntu package)
docker-engine
docker
docker-debuginfo
docker-zsh-completion
docker-bash-completion
docker-fish-completion
moby-engine
app-containers/docker
IBM Cloud Pak System
IBM Cloud Pak for Data Scheduling
IBM Cloud Pak for Business Automation
Dell EMC VxRail Appliance
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
openSUSE Leap
Ubuntu
openEuler
Fedora
ObjectScale
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
Dell PowerProtect Cyber Recovery
QRadar Suite
IBM Cloud Pak for Multicloud Management
Dell EMC Container Storage Modules
docker.io (Ubuntu package)
golang-github-docker-docker-dev (Ubuntu package)
docker-engine
docker
docker-debuginfo
docker-zsh-completion
docker-bash-completion
docker-fish-completion
moby-engine
app-containers/docker
IBM Cloud Pak System
IBM Cloud Pak for Data Scheduling
IBM Cloud Pak for Business Automation
Dell EMC VxRail Appliance
How to mitigate CVE-2023-28841
Install updates from vendor's website.
moby - addressed in versions 20.10.24, 23.0.3
ObjectScale - update to 1.3.0
QRadar Suite - update to 1.10.21.0
IBM Cloud Pak for Multicloud Management - update to 2.3.8
docker.io (Ubuntu package) - update to Ubuntu Pro
golang-github-docker-docker-dev (Ubuntu package) - update to Ubuntu Pro
Dell EMC Container Storage Modules - update to 1.7.0
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
Cloud Pak for Network Automation - update to 2.4.7
IBM Cloud Pak for Watson AIOps - update to 4.1.1
IBM Cloud Pak for Data Scheduling - update to 4.8.0
DB2 on Cloud Pak for Data - update to 4.8.4
Dell EMC VxRail Appliance - update to 8.0.120
docker-engine - update to 18.09.0-253
Dell PowerProtect Cyber Recovery - update to 19.15.0.1
docker - addressed in versions 20.10.25_ce-98.93.1, 24.0.5_ce-150000.185.1
docker-debuginfo - addressed in versions 20.10.25_ce-98.93.1, 24.0.5_ce-150000.185.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 24.0.0-IF001
docker-zsh-completion - update to 24.0.5_ce-150000.185.1
docker-bash-completion - update to 24.0.5_ce-150000.185.1
docker-fish-completion - update to 24.0.5_ce-150000.185.1
moby-engine - addressed in versions 24.0.5-1.fc37, 24.0.5-1.fc38, 24.0.5-1.fc39
app-containers/docker - update to 25.0.4
ObjectScale - update to 1.3.0
QRadar Suite - update to 1.10.21.0
IBM Cloud Pak for Multicloud Management - update to 2.3.8
docker.io (Ubuntu package) - update to Ubuntu Pro
golang-github-docker-docker-dev (Ubuntu package) - update to Ubuntu Pro
Dell EMC Container Storage Modules - update to 1.7.0
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
Cloud Pak for Network Automation - update to 2.4.7
IBM Cloud Pak for Watson AIOps - update to 4.1.1
IBM Cloud Pak for Data Scheduling - update to 4.8.0
DB2 on Cloud Pak for Data - update to 4.8.4
Dell EMC VxRail Appliance - update to 8.0.120
docker-engine - update to 18.09.0-253
Dell PowerProtect Cyber Recovery - update to 19.15.0.1
docker - addressed in versions 20.10.25_ce-98.93.1, 24.0.5_ce-150000.185.1
docker-debuginfo - addressed in versions 20.10.25_ce-98.93.1, 24.0.5_ce-150000.185.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF035, 24.0.0-IF001
docker-zsh-completion - update to 24.0.5_ce-150000.185.1
docker-bash-completion - update to 24.0.5_ce-150000.185.1
docker-fish-completion - update to 24.0.5_ce-150000.185.1
moby-engine - addressed in versions 24.0.5-1.fc37, 24.0.5-1.fc38, 24.0.5-1.fc39
app-containers/docker - update to 25.0.4
External References
- https://github.com/moby/moby/security/advisories/GHSA-6wrf-mxfj-pf5p
- https://github.com/moby/libnetwork/security/advisories/GHSA-gvm4-2qqg-m333
- https://github.com/moby/moby/issues/43382
- https://github.com/moby/moby/security/advisories/GHSA-232p-vwff-86mp
- https://github.com/moby/moby/security/advisories/GHSA-vwm3-crmr-xfxw
- https://github.com/moby/moby/security/advisories/GHSA-33pg-m6jh-5237
- https://github.com/moby/moby/pull/45118
- https://github.com/moby/libnetwork/blob/d9fae4c73daf76c3b0f77e14b45b8bf612ba764d/drivers/overlay/encryption.go#L205-L207
Related Security Bulletins
- Multiple vulnerabilities in Moby
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in Dell Container Storage Modules
- SUSE update for docker
- Fedora 39 update for moby-engine
- Fedora 37 update for moby-engine
- Fedora 38 update for moby-engine
- SUSE update for docker
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Cloud Pak for Data Scheduling
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- openEuler update for docker
- Multiple vulnerabilities in IBM QRadar Suite software
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Gentoo update for Docker
- Ubuntu update for docker.io
- Multiple vulnerabilities in Dell ObjectScale