Incorrect authorization in moby - CVE-2024-41110

 

Incorrect authorization in moby - CVE-2024-41110

Published: July 26, 2024 / Updated: July 29, 2024


Vulnerability identifier: #VU94762
CSH Severity: Medium
CVSS v4: 9.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2024-41110
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to AuthZ zero length regression. A remote user can bypass authentication and gain elevated privileges.


Affected software

moby
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Anolis OS
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
HPC Module
openSUSE Leap
Ubuntu
openEuler
IBM Concert Software
IBM Observability with Instana
APEX Cloud Platform for Red Hat OpenShift
Dell Secure Connect Gateway
QRadar Suite
Guardium Data Security Center (GDSC)
APEX Cloud Platform for Microsoft Azure
OpenManage Network Integration (OMNI)
Cognos Dashboards on Cloud Pak for Data
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Dell Policy Manager for Secure Connect Gateway (SCG)
Robotic Process Automation for Cloud Pak
Intel In-Band Manageability
Dell EMC VxRail Appliance
RSA Authentication Manager
docker.io (Ubuntu package)
golang-github-docker-docker-dev (Ubuntu package)
apptainer-sle15_7
apptainer-leap
apptainer-debuginfo
apptainer-sle15_6
apptainer-sle15_5
apptainer
buildah
docker-engine-debugsource
docker-engine-debuginfo
docker-engine
docker
docker-client
docker-stable
docker-stable-debuginfo
docker-stable-bash-completion
docker-stable-rootless-extras
docker-stable-fish-completion
docker-stable-zsh-completion
docker-debuginfo
docker-zsh-completion
docker-rootless-extras
docker-fish-completion
docker-bash-completion
moby-engine
moby-client
moby
My Cloud Home
My Cloud Home Duo

How to mitigate CVE-2024-41110

Install updates from vendor's website.

moby - addressed in versions 23.0.14, 25.0.6, 26.1.4, 27.1.0
IBM Concert Software - update to 1.1.0
QRadar Suite - update to 1.10.25.0
Guardium Data Security Center (GDSC) - update to 3.7.2
Intel In-Band Manageability - update to 4.2.6
Dell EMC VxRail Appliance - addressed in versions 7.0.540, 8.321
RSA Authentication Manager - update to 8.7 SP2 Patch 6
IBM Observability with Instana - update to 279
docker.io (Ubuntu package) - addressed in versions Ubuntu Pro, 26.1.3-0ubuntu1.1
golang-github-docker-docker-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 26.1.4+dfsg2-1ubuntu1.1
apptainer-sle15_7 - update to 1.3.6-150600.4.9.1
apptainer-leap - update to 1.3.6-150600.4.9.1
apptainer-debuginfo - update to 1.3.6-150600.4.9.1
apptainer-sle15_6 - update to 1.3.6-150600.4.9.1
apptainer-sle15_5 - update to 1.3.6-150600.4.9.1
apptainer - update to 1.3.6-150600.4.9.1
APEX Cloud Platform for Microsoft Azure - update to 01.05.01.00
buildah - update to 1.35.4-150300.8.25.1
APEX Cloud Platform for Red Hat OpenShift - addressed in versions 03.01.02.00, 03.02.04.00
OpenManage Network Integration (OMNI) - update to 3.7
Cognos Dashboards on Cloud Pak for Data - update to 5.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.1
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.26.00.16
Dell Secure Connect Gateway - update to 5.26.00.18
My Cloud Home - update to 9.8.0-102
My Cloud Home Duo - update to 9.8.0-102
docker-engine-debugsource - update to 18.09.0-340
docker-engine-debuginfo - update to 18.09.0-340
docker-engine - addressed in versions 18.09.0-340, 25.0.3-10
docker - addressed in versions 20.10.16-3, 24.0.9-7
docker-client - addressed in versions 20.10.16-3, 24.0.9-7
docker-engine - update to 20.10.16-3
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.17, 23.0.19
docker-stable - addressed in versions 24.0.9_ce-1.5.1, 24.0.9_ce-1.11.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.5.1, 24.0.9_ce-150000.1.8.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-debuginfo - addressed in versions 24.0.9_ce-1.5.1, 24.0.9_ce-1.11.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.5.1, 24.0.9_ce-150000.1.8.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-bash-completion - addressed in versions 24.0.9_ce-1.5.1, 24.0.9_ce-1.11.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.5.1, 24.0.9_ce-150000.1.8.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-rootless-extras - addressed in versions 24.0.9_ce-150000.1.5.1, 24.0.9_ce-150000.1.8.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-fish-completion - addressed in versions 24.0.9_ce-150000.1.5.1, 24.0.9_ce-150000.1.8.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-zsh-completion - addressed in versions 24.0.9_ce-150000.1.5.1, 24.0.9_ce-150000.1.8.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker - update to 25.0.3-10
docker-debuginfo - update to 25.0.3-10
docker-client - update to 25.0.3-10
docker-debuginfo - addressed in versions 25.0.6_ce-98.115.1, 25.0.6_ce-150000.203.1, 25.0.6_ce-150000.207.1, 26.1.5_ce-98.120.1, 26.1.5_ce-150000.212.1, 27.5.1_ce-98.126.1, 27.5.1_ce-150000.218.1
docker - addressed in versions 25.0.6_ce-98.115.1, 25.0.6_ce-150000.203.1, 25.0.6_ce-150000.207.1, 26.1.5_ce-98.120.1, 26.1.5_ce-150000.212.1, 27.5.1_ce-98.126.1, 27.5.1_ce-150000.218.1
docker-zsh-completion - addressed in versions 25.0.6_ce-150000.203.1, 25.0.6_ce-150000.207.1, 26.1.5_ce-150000.212.1, 27.5.1_ce-150000.218.1
docker-rootless-extras - addressed in versions 25.0.6_ce-150000.203.1, 25.0.6_ce-150000.207.1, 26.1.5_ce-150000.212.1, 27.5.1_ce-150000.218.1
docker-fish-completion - addressed in versions 25.0.6_ce-150000.203.1, 25.0.6_ce-150000.207.1, 26.1.5_ce-150000.212.1, 27.5.1_ce-150000.218.1
docker-bash-completion - addressed in versions 25.0.6_ce-150000.203.1, 25.0.6_ce-150000.207.1, 26.1.5_ce-98.120.1, 26.1.5_ce-150000.212.1, 27.5.1_ce-98.126.1, 27.5.1_ce-150000.218.1
moby-engine - update to 28.3.3-1
moby-client - update to 28.3.3-1
moby - update to 28.3.3-1

External References

Related Security Bulletins