---
id: CVE-2023-28842
title: >-
  moby: Encrypted overlay network with a single endpoint is unauthenticated
  (CVE-2023-28842)
summary: >-
  A vulnerability was found in Moby due to an unprotected alternate channel
  within encrypted overlay networks, which could allow a remote attacker to
  bypass security restrictions. By sending a specially crafted request, an
  attacker could inj…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N'
cvssSource: vendor
cwe: CWE-420
vendor: Red Hat
product: multicluster engine for Kubernetes 2.4 for RHEL 8
affected:
  - multicluster_engine_for_kubernetes_2_4_for_rhel 8
patched:
  - multicluster_engine_for_kubernetes_2_4_for_rhel 8
published: '2023-04-04'
updated: '2026-09-19'
sourceUpdated: '2026-09-19T17:40:39+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-28842.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-28842.json
  - url: 'https://access.redhat.com/security/cve/CVE-2023-28842'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2184688'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2023-28842'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-28842'
  - url: 'https://github.com/moby/moby/security/advisories/GHSA-6wrf-mxfj-pf5p'
  - url: 'https://access.redhat.com/errata/RHBA-2024:1246'
  - url: 'https://github.com/moby/libnetwork/security/advisories/GHSA-gvm4-2qqg-m333'
  - url: 'https://github.com/moby/moby/security/advisories/GHSA-232p-vwff-86mp'
  - url: 'https://github.com/moby/moby/security/advisories/GHSA-33pg-m6jh-5237'
  - url: 'https://github.com/moby/moby/security/advisories/GHSA-vwm3-crmr-xfxw'
  - url: 'https://github.com/moby/moby'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.0144
epssPercentile: 0.72028
aliases:
  - GHSA-6wrf-mxfj-pf5p
  - GO-2023-1701
ecosystem: go
ingestedAt: '2026-09-12T03:13:01.761Z'
---

## Overview

A vulnerability was found in Moby due to an unprotected alternate channel within encrypted overlay networks, which could allow a remote attacker to bypass security restrictions. By sending a specially crafted request, an attacker could inject arbitrary Ethernet frames into the encrypted overlay network by encapsulating them in VXLAN datagrams.

## Vendor advisories

- **RHBA-2024:1246** · Red Hat · fixed in: multicluster engine for Kubernetes 2.4 for RHEL 8 · released 2024-03-11 · [advisory](https://access.redhat.com/errata/RHBA-2024:1246)

**moby: Encrypted overlay network with a single endpoint is unauthenticated** — rated Moderate by Red Hat. Released 2023-04-04, updated 2026-09-19.

Fixed:

- multicluster engine for Kubernetes 2.4 for RHEL 8

Not affected:

- OpenShift Service Mesh 2
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat Advanced Cluster Security 3
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift Container Platform Assisted Installer 1
- Red Hat Quay 3

## Remediation

For multicluster engine for Kubernetes, see the following documentation for
details on how to install the images:

https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/clusters/cluster_mce_overview#installing-while-connected-online-mce https://access.redhat.com/errata/RHBA-2024:1246

## Package advisory (CVE-2023-28842)

Affected packages:

- `github.com/docker/docker >= 1.12.0, < 20.10.24`
- `github.com/docker/docker >= 23.0.0, < 23.0.3`

Patched in:

- `github.com/docker/docker 20.10.24`
- `github.com/docker/docker 23.0.3`

Source: https://osv.dev/vulnerability/GHSA-6wrf-mxfj-pf5p
