Incorrect authorization in moby - CVE-2024-41110
Published: July 26, 2024 / Updated: July 29, 2024
Vulnerability identifier: #VU94762
CSH Severity: Medium
CVSS v4: 9.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2024-41110
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to AuthZ zero length regression. A remote user can bypass authentication and gain elevated privileges.
Affected software
moby
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Anolis OS
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
HPC Module
openSUSE Leap
Ubuntu
openEuler
IBM Concert Software
IBM Observability with Instana
APEX Cloud Platform for Red Hat OpenShift
Dell Secure Connect Gateway
QRadar Suite
Guardium Data Security Center (GDSC)
APEX Cloud Platform for Microsoft Azure
OpenManage Network Integration (OMNI)
Cognos Dashboards on Cloud Pak for Data
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Dell Policy Manager for Secure Connect Gateway (SCG)
Robotic Process Automation for Cloud Pak
Intel In-Band Manageability
Dell EMC VxRail Appliance
RSA Authentication Manager
docker.io (Ubuntu package)
golang-github-docker-docker-dev (Ubuntu package)
apptainer-sle15_7
apptainer-leap
apptainer-debuginfo
apptainer-sle15_6
apptainer-sle15_5
apptainer
buildah
docker-engine-debugsource
docker-engine-debuginfo
docker-engine
docker
docker-client
docker-stable
docker-stable-debuginfo
docker-stable-bash-completion
docker-stable-rootless-extras
docker-stable-fish-completion
docker-stable-zsh-completion
docker-debuginfo
docker-zsh-completion
docker-rootless-extras
docker-fish-completion
docker-bash-completion
moby-engine
moby-client
moby
My Cloud Home
My Cloud Home Duo
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Anolis OS
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
HPC Module
openSUSE Leap
Ubuntu
openEuler
IBM Concert Software
IBM Observability with Instana
APEX Cloud Platform for Red Hat OpenShift
Dell Secure Connect Gateway
QRadar Suite
Guardium Data Security Center (GDSC)
APEX Cloud Platform for Microsoft Azure
OpenManage Network Integration (OMNI)
Cognos Dashboards on Cloud Pak for Data
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Dell Policy Manager for Secure Connect Gateway (SCG)
Robotic Process Automation for Cloud Pak
Intel In-Band Manageability
Dell EMC VxRail Appliance
RSA Authentication Manager
docker.io (Ubuntu package)
golang-github-docker-docker-dev (Ubuntu package)
apptainer-sle15_7
apptainer-leap
apptainer-debuginfo
apptainer-sle15_6
apptainer-sle15_5
apptainer
buildah
docker-engine-debugsource
docker-engine-debuginfo
docker-engine
docker
docker-client
docker-stable
docker-stable-debuginfo
docker-stable-bash-completion
docker-stable-rootless-extras
docker-stable-fish-completion
docker-stable-zsh-completion
docker-debuginfo
docker-zsh-completion
docker-rootless-extras
docker-fish-completion
docker-bash-completion
moby-engine
moby-client
moby
My Cloud Home
My Cloud Home Duo
How to mitigate CVE-2024-41110
Install updates from vendor's website.
moby - addressed in versions 23.0.14, 25.0.6, 26.1.4, 27.1.0
IBM Concert Software - update to 1.1.0
QRadar Suite - update to 1.10.25.0
Guardium Data Security Center (GDSC) - update to 3.7.2
Intel In-Band Manageability - update to 4.2.6
Dell EMC VxRail Appliance - addressed in versions 7.0.540, 8.321
RSA Authentication Manager - update to 8.7 SP2 Patch 6
IBM Observability with Instana - update to 279
docker.io (Ubuntu package) - addressed in versions Ubuntu Pro, 26.1.3-0ubuntu1.1
golang-github-docker-docker-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 26.1.4+dfsg2-1ubuntu1.1
apptainer-sle15_7 - update to 1.3.6-150600.4.9.1
apptainer-leap - update to 1.3.6-150600.4.9.1
apptainer-debuginfo - update to 1.3.6-150600.4.9.1
apptainer-sle15_6 - update to 1.3.6-150600.4.9.1
apptainer-sle15_5 - update to 1.3.6-150600.4.9.1
apptainer - update to 1.3.6-150600.4.9.1
APEX Cloud Platform for Microsoft Azure - update to 01.05.01.00
buildah - update to 1.35.4-150300.8.25.1
APEX Cloud Platform for Red Hat OpenShift - addressed in versions 03.01.02.00, 03.02.04.00
OpenManage Network Integration (OMNI) - update to 3.7
Cognos Dashboards on Cloud Pak for Data - update to 5.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.1
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.26.00.16
Dell Secure Connect Gateway - update to 5.26.00.18
My Cloud Home - update to 9.8.0-102
My Cloud Home Duo - update to 9.8.0-102
docker-engine-debugsource - update to 18.09.0-340
docker-engine-debuginfo - update to 18.09.0-340
docker-engine - addressed in versions 18.09.0-340, 25.0.3-10
docker - addressed in versions 20.10.16-3, 24.0.9-7
docker-client - addressed in versions 20.10.16-3, 24.0.9-7
docker-engine - update to 20.10.16-3
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.17, 23.0.19
docker-stable - addressed in versions 24.0.9_ce-1.5.1, 24.0.9_ce-1.11.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.5.1, 24.0.9_ce-150000.1.8.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-debuginfo - addressed in versions 24.0.9_ce-1.5.1, 24.0.9_ce-1.11.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.5.1, 24.0.9_ce-150000.1.8.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-bash-completion - addressed in versions 24.0.9_ce-1.5.1, 24.0.9_ce-1.11.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.5.1, 24.0.9_ce-150000.1.8.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-rootless-extras - addressed in versions 24.0.9_ce-150000.1.5.1, 24.0.9_ce-150000.1.8.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-fish-completion - addressed in versions 24.0.9_ce-150000.1.5.1, 24.0.9_ce-150000.1.8.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-zsh-completion - addressed in versions 24.0.9_ce-150000.1.5.1, 24.0.9_ce-150000.1.8.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker - update to 25.0.3-10
docker-debuginfo - update to 25.0.3-10
docker-client - update to 25.0.3-10
docker-debuginfo - addressed in versions 25.0.6_ce-98.115.1, 25.0.6_ce-150000.203.1, 25.0.6_ce-150000.207.1, 26.1.5_ce-98.120.1, 26.1.5_ce-150000.212.1, 27.5.1_ce-98.126.1, 27.5.1_ce-150000.218.1
docker - addressed in versions 25.0.6_ce-98.115.1, 25.0.6_ce-150000.203.1, 25.0.6_ce-150000.207.1, 26.1.5_ce-98.120.1, 26.1.5_ce-150000.212.1, 27.5.1_ce-98.126.1, 27.5.1_ce-150000.218.1
docker-zsh-completion - addressed in versions 25.0.6_ce-150000.203.1, 25.0.6_ce-150000.207.1, 26.1.5_ce-150000.212.1, 27.5.1_ce-150000.218.1
docker-rootless-extras - addressed in versions 25.0.6_ce-150000.203.1, 25.0.6_ce-150000.207.1, 26.1.5_ce-150000.212.1, 27.5.1_ce-150000.218.1
docker-fish-completion - addressed in versions 25.0.6_ce-150000.203.1, 25.0.6_ce-150000.207.1, 26.1.5_ce-150000.212.1, 27.5.1_ce-150000.218.1
docker-bash-completion - addressed in versions 25.0.6_ce-150000.203.1, 25.0.6_ce-150000.207.1, 26.1.5_ce-98.120.1, 26.1.5_ce-150000.212.1, 27.5.1_ce-98.126.1, 27.5.1_ce-150000.218.1
moby-engine - update to 28.3.3-1
moby-client - update to 28.3.3-1
moby - update to 28.3.3-1
IBM Concert Software - update to 1.1.0
QRadar Suite - update to 1.10.25.0
Guardium Data Security Center (GDSC) - update to 3.7.2
Intel In-Band Manageability - update to 4.2.6
Dell EMC VxRail Appliance - addressed in versions 7.0.540, 8.321
RSA Authentication Manager - update to 8.7 SP2 Patch 6
IBM Observability with Instana - update to 279
docker.io (Ubuntu package) - addressed in versions Ubuntu Pro, 26.1.3-0ubuntu1.1
golang-github-docker-docker-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 26.1.4+dfsg2-1ubuntu1.1
apptainer-sle15_7 - update to 1.3.6-150600.4.9.1
apptainer-leap - update to 1.3.6-150600.4.9.1
apptainer-debuginfo - update to 1.3.6-150600.4.9.1
apptainer-sle15_6 - update to 1.3.6-150600.4.9.1
apptainer-sle15_5 - update to 1.3.6-150600.4.9.1
apptainer - update to 1.3.6-150600.4.9.1
APEX Cloud Platform for Microsoft Azure - update to 01.05.01.00
buildah - update to 1.35.4-150300.8.25.1
APEX Cloud Platform for Red Hat OpenShift - addressed in versions 03.01.02.00, 03.02.04.00
OpenManage Network Integration (OMNI) - update to 3.7
Cognos Dashboards on Cloud Pak for Data - update to 5.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.1
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.26.00.16
Dell Secure Connect Gateway - update to 5.26.00.18
My Cloud Home - update to 9.8.0-102
My Cloud Home Duo - update to 9.8.0-102
docker-engine-debugsource - update to 18.09.0-340
docker-engine-debuginfo - update to 18.09.0-340
docker-engine - addressed in versions 18.09.0-340, 25.0.3-10
docker - addressed in versions 20.10.16-3, 24.0.9-7
docker-client - addressed in versions 20.10.16-3, 24.0.9-7
docker-engine - update to 20.10.16-3
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.17, 23.0.19
docker-stable - addressed in versions 24.0.9_ce-1.5.1, 24.0.9_ce-1.11.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.5.1, 24.0.9_ce-150000.1.8.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-debuginfo - addressed in versions 24.0.9_ce-1.5.1, 24.0.9_ce-1.11.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.5.1, 24.0.9_ce-150000.1.8.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-bash-completion - addressed in versions 24.0.9_ce-1.5.1, 24.0.9_ce-1.11.1, 24.0.9_ce-1.32.1, 24.0.9_ce-150000.1.5.1, 24.0.9_ce-150000.1.8.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-rootless-extras - addressed in versions 24.0.9_ce-150000.1.5.1, 24.0.9_ce-150000.1.8.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-fish-completion - addressed in versions 24.0.9_ce-150000.1.5.1, 24.0.9_ce-150000.1.8.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker-stable-zsh-completion - addressed in versions 24.0.9_ce-150000.1.5.1, 24.0.9_ce-150000.1.8.1, 24.0.9_ce-150000.1.11.1, 24.0.9_ce-150000.1.15.1, 24.0.9_ce-150000.1.39.1
docker - update to 25.0.3-10
docker-debuginfo - update to 25.0.3-10
docker-client - update to 25.0.3-10
docker-debuginfo - addressed in versions 25.0.6_ce-98.115.1, 25.0.6_ce-150000.203.1, 25.0.6_ce-150000.207.1, 26.1.5_ce-98.120.1, 26.1.5_ce-150000.212.1, 27.5.1_ce-98.126.1, 27.5.1_ce-150000.218.1
docker - addressed in versions 25.0.6_ce-98.115.1, 25.0.6_ce-150000.203.1, 25.0.6_ce-150000.207.1, 26.1.5_ce-98.120.1, 26.1.5_ce-150000.212.1, 27.5.1_ce-98.126.1, 27.5.1_ce-150000.218.1
docker-zsh-completion - addressed in versions 25.0.6_ce-150000.203.1, 25.0.6_ce-150000.207.1, 26.1.5_ce-150000.212.1, 27.5.1_ce-150000.218.1
docker-rootless-extras - addressed in versions 25.0.6_ce-150000.203.1, 25.0.6_ce-150000.207.1, 26.1.5_ce-150000.212.1, 27.5.1_ce-150000.218.1
docker-fish-completion - addressed in versions 25.0.6_ce-150000.203.1, 25.0.6_ce-150000.207.1, 26.1.5_ce-150000.212.1, 27.5.1_ce-150000.218.1
docker-bash-completion - addressed in versions 25.0.6_ce-150000.203.1, 25.0.6_ce-150000.207.1, 26.1.5_ce-98.120.1, 26.1.5_ce-150000.212.1, 27.5.1_ce-98.126.1, 27.5.1_ce-150000.218.1
moby-engine - update to 28.3.3-1
moby-client - update to 28.3.3-1
moby - update to 28.3.3-1
External References
- https://github.com/moby/moby/security/advisories/GHSA-v23v-6jw2-98fq
- https://github.com/moby/moby/commit/411e817ddf710ff8e08fa193da80cb78af708191
- https://github.com/moby/moby/commit/42f40b1d6dd7562342f832b9cd2adf9e668eeb76
- https://github.com/moby/moby/commit/65cc597cea28cdc25bea3b8a86384b4251872919
- https://github.com/moby/moby/commit/852759a7df454cbf88db4e954c919becd48faa9b
- https://github.com/moby/moby/commit/a31260625655cff9ae226b51757915e275e304b0
- https://github.com/moby/moby/commit/a79fabbfe84117696a19671f4aa88b82d0f64fc1
- https://github.com/moby/moby/commit/ae160b4edddb72ef4bd71f66b975a1a1cc434f00
- https://github.com/moby/moby/commit/ae2b3666c517c96cbc2adf1af5591a6b00d4ec0f
- https://github.com/moby/moby/commit/cc13f952511154a2866bddbb7dddebfe9e83b801
- https://github.com/moby/moby/commit/fc274cd2ff4cf3b48c91697fb327dd1fb95588fb
- https://www.docker.com/blog/docker-security-advisory-docker-engine-authz-plugin
- https://github.com/moby/moby/releases/tag/v25.0.6
Related Security Bulletins
- Incorrect authorization in Moby
- SUSE update for docker
- SUSE update for docker
- SUSE update for docker
- openEuler update for docker
- Incorrect authorization in IBM Observability with Instana
- openEuler 24.03 LTS update for moby
- SUSE update for buildah, docker
- Multiple vulnerabilities in IBM QRadar Suite software
- intel-inb-manageability update for Moby
- Multiple vulnerabilities in Dell Secure Connect Gateway Policy Manager
- IBM Robotic Process Automation for Cloud Pak update for Moby
- SUSE update for docker-stable
- SUSE update for docker-stable
- SUSE update for docker
- Ubuntu update for docker.io
- SUSE update for docker
- SUSE update for Recommended update for docker-stable
- Multiple vulnerabilities in Dell OpenManage Network Integration (OMNI)
- Multiple vulnerabilities in Dell Secure Connect Gateway
- SUSE update for docker-stable
- Ubuntu update for docker.io
- IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for Moby
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- SUSE update for apptainer
- Dell VxRail Appliance 7.x update for third-party components
- Dell VxRail Appliance 8.x update for third-party components
- SUSE update for docker, docker-stable
- SUSE update for docker, docker-stable
- Ubuntu update for docker.io
- Multiple vulnerabilities in Western Digital My Cloud Home and Duo
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- RSA Authentication Manager update for third-party components
- Multiple vulnerabilities in Dell APEX Cloud Platform for Red Hat OpenShift
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in IBM Concert Software
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- Anolis OS update for docker
- Anolis OS update for moby
- Anolis OS update for docker
- SUSE update for docker-stable
- SUSE update for docker-stable