Skip to content

Latest commit

 

History

History
27 lines (25 loc) · 1.07 KB

0007.md

File metadata and controls

27 lines (25 loc) · 1.07 KB

MCR: Encrypted overlay network may be unauthenticated

Release Date

2023-04-04

Overview

Swarm encrypted overlay networks may not enforce their authentication guarantees in some situations.

Consult the upstream advisory for details, mitigations, workarounds, and patches.

Affected Products

Mirantis Container Runtime (MCR) <= 20.10.16 or <= 23.0.3

Vulnerability Information

CVE Identifier

CVE-2023-28840

CVSSv3.1

7.5 (High) CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:L

CWEs

CWE-420, CWE-636

Acknowledgements

Found by the MCR team, with assistance from the Moby community

Disclosure Timeline

  • 2023-04-04: MCR 23.0.3 and 20.10.16 released, security advisories disclosed
  • 2023-04-30: Timeline for disclosure finalized with partners
  • 2023-04-23: Patches pass internal validation and test plan
  • 2023-03-22: Patches code-complete and code-reviewed
  • 2023-03-09: Upstream partners alerted
  • 2023-03-08: Security issue identified by MCR team