CVE-2020-13401Improper Input Validation in Docker Docker-ce

Severity
6.0MEDIUMNVD
EPSS
12.9%
top 5.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 2
Latest updateJun 7

Description

An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:LExploitability: 1.8 | Impact: 3.7

Affected Packages2 packages

NVDdocker/engine< 19.03.11

Also affects: Debian Linux 10.0, Fedora 31, 32

🔴Vulnerability Details

4
OSV
Improper Input Validation in Docker Engine2022-02-15
GHSA
Improper Input Validation in Docker Engine2022-02-15
OSV
CVE-2020-13401: An issue was discovered in Docker Engine before 192020-06-02
CVEList
CVE-2020-13401: An issue was discovered in Docker Engine before 192020-06-02

📋Vendor Advisories

2
Red Hat
docker: IPv6 router advertisements allow for MitM attacks2020-06-01
Debian
CVE-2020-13401: docker.io - An issue was discovered in Docker Engine before 19.03.11. An attacker in a conta...2020

📄Research Papers

1
arXiv
Towards a Security Stress-Test for Cloud Configurations2022-06-07

💬Community

1
Bugzilla
CVE-2020-13401 docker: IPv6 router advertisements allow for MitM attacks2020-05-08
CVE-2020-13401 — Improper Input Validation | cvebase