Bug 2270591 (CVE-2024-29018)
Summary: | CVE-2024-29018 moby: external DNS requests from 'internal' networks could lead to data exfiltration | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | TEJ RATHI <trathi> |
Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
Status: | NEW --- | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | amctagga, aoconnor, asatyam, bdettelb, bniver, dhanak, diagrawa, dkenigsb, dsimansk, dymurray, eglynn, fdeutsch, flucifre, gkamathe, gmeno, gparvin, hhorak, ibolton, jcantril, jjoyce, jkoehler, jmatthew, jmontleo, joelsmith, jorton, jschluet, jwendell, kingland, kverlaen, lbainbri, lgamliel, lhh, lsvaty, matzew, mbenjamin, mburns, mgarciac, mhackett, mnovotny, mrajanna, muagarwa, mwringe, nbecker, njean, odf-bz-bot, oramraz, owatkins, pahickey, pgrist, pierdipi, rcernich, rfreiman, rguimara, rhaigner, rhos-maint, rhuss, rjohnson, sabiswas, sapillai, sdawley, sipoyare, slucidi, smullick, sostapov, sseago, thrcka, tnielsen, twalsh, vereddy, whayutin |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | moby 26.0.0-rc3, moby 25.0.5, moby 23.0.11 | Doc Type: | If docs needed, set a value |
Doc Text: |
A vulnerability was found in Moby due to excessive data output in external DNS requests from "internal" networks, enabling unauthorized access to sensitive system information by remote attackers. This flaw allows attackers to gain access to sensitive information by exploiting incorrect resource transfer between spheres through specially crafted requests.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2270600, 2270601, 2270602, 2306548, 2306550, 2270599, 2270603, 2270604, 2270605, 2270606, 2270607, 2270608, 2270609, 2270610, 2270612, 2270613, 2270614, 2270615, 2270626, 2282262 | ||
Bug Blocks: | 2270637 |
Description
TEJ RATHI
2024-03-21 05:04:54 UTC
Created apptainer tracking bugs for this issue: Affects: epel-all [bug 2270599] Affects: fedora-all [bug 2270604] Created cri-tools tracking bugs for this issue: Affects: fedora-all [bug 2270605] Created kompose tracking bugs for this issue: Affects: epel-all [bug 2270600] Created manifest-tool tracking bugs for this issue: Affects: epel-all [bug 2270601] Created moby-engine tracking bugs for this issue: Affects: fedora-all [bug 2270606] Created osbuild-composer tracking bugs for this issue: Affects: fedora-all [bug 2270607] Created pack tracking bugs for this issue: Affects: epel-all [bug 2270602] Affects: fedora-all [bug 2270608] Created singularity-ce tracking bugs for this issue: Affects: epel-all [bug 2270603] Affects: fedora-all [bug 2270609] Created source-to-image tracking bugs for this issue: Affects: fedora-all [bug 2270610] Created golang-github-docker tracking bugs for this issue: Affects: fedora-all [bug 2282262] This issue has been addressed in the following products: Red Hat Migration Toolkit for Containers 1.8 Via RHSA-2024:7164 https://access.redhat.com/errata/RHSA-2024:7164 |