Skip to content

Security issues in encrypted overlay networks

High
thaJeztah published GHSA-gvm4-2qqg-m333 Apr 4, 2023

Package

gomod github.com/docker/libnetwork (Go)

Affected versions

>= 1.12

Patched versions

>= 23.0.3, >= 20.10.24

Description

Three CVEs affecting all versions of Swarm encrypted overlay networks have been discovered:

Additionally, there is an informational security advisory regarding a documentation issue:

This security advisory is to draw attention to these advisories, which are tracked on the new canonical repository for libnetwork, moby/moby. As this repository is still in use for the 20.10 branch of Moby, users should consult the advisories, perform mitigations, and update as soon as is practical.

Severity

High

CVE ID

No known CVE

Weaknesses

No CWEs

Credits