CVE-2020-13401
MEDIUM6.0EPSS 4.7%docker.io - security update
發布日:2022/2/15修改日:2026/4/28
也稱為:DEBIAN-CVE-2020-13401
描述
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.
受影響套件(3)
- Debian/docker.iofrom 0, < 19.03.11+dfsg1-1
- Debian/docker.iofrom 0, < 18.09.1+dfsg1-7.1+deb10u2
- Go/github.com/docker/docker-cefrom 0, < 19.03.11
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.0 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L |
參考連結(11)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2020-13401
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2020-13401
- WEBhttp://lists.opensuse.org/opensuse-security-announce/2020-06/msg00040.html
- WEBhttps://docs.docker.com/engine/release-notes
- WEBhttps://github.com/docker/docker-ce/releases/tag/v19.03.11
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/DN4JQAOXBE3XUNK3FD423LHE3K74EMJT
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/KJZLKRCOJMOGUIJI2AS27BOZS3RBEF3K
- WEBhttps://security.gentoo.org/glsa/202008-15
- WEBhttps://security.netapp.com/advisory/ntap-20200717-0002
- WEBhttps://www.debian.org/security/2020/dsa-4716
- WEBhttp://www.openwall.com/lists/oss-security/2020/06/01/5