Skip to content

Docker CVE-2020-13401

Moderate
etungsten published GHSA-67fp-jghp-c759 Aug 17, 2020

Package

Docker (bottlerocket)

Affected versions

< 0.5.0

Patched versions

0.5.0

Description

A flaw was found in Docker when it creates network bridges that accept IPv6 router advertisements by default. This flaw allows an attacker who can execute code in a container to possibly spoof rogue IPv6 router advertisements to perform a man-in-the-middle (MitM) attack against the host network or another container.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13401
https://www.openwall.com/lists/oss-security/2020/06/01/5

Severity

Moderate

CVE ID

CVE-2020-13401

Weaknesses

No CWEs