CVE-2020-13401
published 2020-06-02CVE-2020-13401: An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements…
PriorityP431medium6CVSS 3.1
AVNACHPRLUINSCCLILAL
EPSS
2.84%
85.1th percentile
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | docker.io | < docker.io 19.03.11+dfsg1-1 (bookworm) | docker.io 19.03.11+dfsg1-1 (bookworm) |
| docker | engine | < 19.03.11 | 19.03.11 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| github.com | docker_docker-ce | >= 0 < 19.03.11 | 19.03.11 |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Input Validation in Docker Engine
osv·2022-02-15
CVE-2020-13401 [MEDIUM] Improper Input Validation in Docker Engine
Improper Input Validation in Docker Engine
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.
GHSA
Improper Input Validation in Docker Engine
ghsa·2022-02-15
CVE-2020-13401 [MEDIUM] CWE-20 Improper Input Validation in Docker Engine
Improper Input Validation in Docker Engine
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.
OSV
CVE-2020-13401: An issue was discovered in Docker Engine before 19
osv·2020-06-02·CVSS 6.0
CVE-2020-13401 [MEDIUM] CVE-2020-13401: An issue was discovered in Docker Engine before 19
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.
Red Hat
docker: IPv6 router advertisements allow for MitM attacks
vendor_redhat·2020-06-01·CVSS 6.0
CVE-2020-13401 [MEDIUM] CWE-300 docker: IPv6 router advertisements allow for MitM attacks
docker: IPv6 router advertisements allow for MitM attacks
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.
A flaw was found in Docker when it creates network bridges that accept IPv6 router advertisements by default. This flaw allows an attacker who can execute code in a container to possibly spoof rogue IPv6 router advertisements to perform a man-in-the-middle (MitM) attack against the host network or another container.
Mitigation: Prevent untrusted, non-privileged containers from running with CAP_NET_RAW.
Package: docker (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2020-13401: docker.io - An issue was discovered in Docker Engine before 19.03.11. An attacker in a conta...
vendor_debian·2020·CVSS 6.0
CVE-2020-13401 [MEDIUM] CVE-2020-13401: docker.io - An issue was discovered in Docker Engine before 19.03.11. An attacker in a conta...
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.
Scope: local
bookworm: resolved (fixed in 19.03.11+dfsg1-1)
bullseye: resolved (fixed in 19.03.11+dfsg1-1)
forky: resolved (fixed in 19.03.11+dfsg1-1)
sid: resolved (fixed in 19.03.11+dfsg1-1)
trixie: resolved (fixed in 19.03.11+dfsg1-1)
No detection rules found.
No public exploits indexed.
arXiv
Towards a Security Stress-Test for Cloud Configurations
arxiv_fulltext·2022-06-07
Towards a Security Stress-Test for Cloud Configurations
Towards a Security Stress-Test for Cloud Configurations
This work has received funding from the European Union under the H2020 grant 952647 (AssureMOSS).
1st Francesco Minna
Vrije Universiteit Amsterdam (NL)
[email protected]
2nd Fabio Massacci
University of Trento (IT)
Vrije Universiteit Amsterdam (NL)
[email protected]
3rd Katja Tuma
Vrije Universiteit Amsterdam (NL)
[email protected]
## Abstract
Securing cloud configurations is an elusive task, which is left up to system administrators who have to base their decisions on ``trial and error'' experimentations or by observing good practices (e.g., CIS Benchmarks).
We propose a knowledge, AND/OR, graphs approach to model cloud deployment security objects and vulnerabilities. In this way, we can capture relationships between configura
Bugzilla
CVE-2020-13401 docker: IPv6 router advertisements allow for MitM attacks
bugzilla·2020-05-08·CVSS 6.0
CVE-2020-13401 [MEDIUM] CVE-2020-13401 docker: IPv6 router advertisements allow for MitM attacks
CVE-2020-13401 docker: IPv6 router advertisements allow for MitM attacks
Docker creates network bridges that accept IPv6 router advertisements by default. An attacker able to execute code in a container could exploit this to spoof rogue IPv6 router advertisements to perform a MitM attack against the host network.
Discussion:
Acknowledgments:
Name: the Kubernetes Product Security Committee
Upstream: Etienne Champetier
---
Mitigation:
Prevent untrusted, non-privileged containers from running with CAP_NET_RAW.
---
Upstream Patch:
https://github.com/moby/libnetwork/commit/153d0769a1181bf591a9637fd487a541ec7db1e6
---
External References:
https://groups.google.com/forum/#!topic/kubernetes-security-announce/BMb_6ICCfp8
https://docs.docker.com/engine/release-notes/#190311
---
quay.i
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00040.htmlhttp://www.openwall.com/lists/oss-security/2020/06/01/5https://docs.docker.com/engine/release-notes/https://github.com/docker/docker-ce/releases/tag/v19.03.11https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DN4JQAOXBE3XUNK3FD423LHE3K74EMJT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJZLKRCOJMOGUIJI2AS27BOZS3RBEF3K/https://security.gentoo.org/glsa/202008-15https://security.netapp.com/advisory/ntap-20200717-0002/https://www.debian.org/security/2020/dsa-4716http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00040.htmlhttp://www.openwall.com/lists/oss-security/2020/06/01/5https://docs.docker.com/engine/release-notes/https://github.com/docker/docker-ce/releases/tag/v19.03.11https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DN4JQAOXBE3XUNK3FD423LHE3K74EMJT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJZLKRCOJMOGUIJI2AS27BOZS3RBEF3K/https://security.gentoo.org/glsa/202008-15https://security.netapp.com/advisory/ntap-20200717-0002/https://www.debian.org/security/2020/dsa-4716
2020-06-02
Published