{"id":"CVE-2023-28842","title":"moby: Encrypted overlay network with a single endpoint is unauthenticated (CVE-2023-28842)","summary":"A vulnerability was found in Moby due to an unprotected alternate channel within encrypted overlay networks, which could allow a remote attacker to bypass security restrictions. By sending a specially crafted request, an attacker could inj…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","cvssSource":"vendor","cwe":"CWE-420","vendor":"Red Hat","product":"multicluster engine for Kubernetes 2.4 for RHEL 8","affected":["multicluster_engine_for_kubernetes_2_4_for_rhel 8"],"patched":["multicluster_engine_for_kubernetes_2_4_for_rhel 8"],"published":"2023-04-04","updated":"2026-09-19","sourceUpdated":"2026-09-19T17:40:39+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-28842.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-28842.json"},{"url":"https://access.redhat.com/security/cve/CVE-2023-28842"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2184688"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-28842"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-28842"},{"url":"https://github.com/moby/moby/security/advisories/GHSA-6wrf-mxfj-pf5p"},{"url":"https://access.redhat.com/errata/RHBA-2024:1246"},{"url":"https://github.com/moby/libnetwork/security/advisories/GHSA-gvm4-2qqg-m333"},{"url":"https://github.com/moby/moby/security/advisories/GHSA-232p-vwff-86mp"},{"url":"https://github.com/moby/moby/security/advisories/GHSA-33pg-m6jh-5237"},{"url":"https://github.com/moby/moby/security/advisories/GHSA-vwm3-crmr-xfxw"},{"url":"https://github.com/moby/moby"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.0144,"epssPercentile":0.72024,"aliases":["GHSA-6wrf-mxfj-pf5p","GO-2023-1701"],"ecosystem":"go","ingestedAt":"2026-09-12T03:13:01.761Z","slug":"CVE-2023-28842","body":"## Overview\n\nA vulnerability was found in Moby due to an unprotected alternate channel within encrypted overlay networks, which could allow a remote attacker to bypass security restrictions. By sending a specially crafted request, an attacker could inject arbitrary Ethernet frames into the encrypted overlay network by encapsulating them in VXLAN datagrams.\n\n## Vendor advisories\n\n- **RHBA-2024:1246** · Red Hat · fixed in: multicluster engine for Kubernetes 2.4 for RHEL 8 · released 2024-03-11 · [advisory](https://access.redhat.com/errata/RHBA-2024:1246)\n\n**moby: Encrypted overlay network with a single endpoint is unauthenticated** — rated Moderate by Red Hat. Released 2023-04-04, updated 2026-09-19.\n\nFixed:\n\n- multicluster engine for Kubernetes 2.4 for RHEL 8\n\nNot affected:\n\n- OpenShift Service Mesh 2\n- Red Hat Advanced Cluster Management for Kubernetes 2\n- Red Hat Advanced Cluster Security 3\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Container Platform Assisted Installer 1\n- Red Hat Quay 3\n\n## Remediation\n\nFor multicluster engine for Kubernetes, see the following documentation for\ndetails on how to install the images:\n\nhttps://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/clusters/cluster_mce_overview#installing-while-connected-online-mce https://access.redhat.com/errata/RHBA-2024:1246\n\n## Package advisory (CVE-2023-28842)\n\nAffected packages:\n\n- `github.com/docker/docker >= 1.12.0, < 20.10.24`\n- `github.com/docker/docker >= 23.0.0, < 23.0.3`\n\nPatched in:\n\n- `github.com/docker/docker 20.10.24`\n- `github.com/docker/docker 23.0.3`\n\nSource: https://osv.dev/vulnerability/GHSA-6wrf-mxfj-pf5p","depth":"sunlit","depthScore":38,"depthScoreParts":{"impact":37.4,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}