VDB
Sign up
MEDIUM6.0

GHSA-qrrc-ww9x-r43g

Improper Input Validation in Docker Engine

Quick fix

GHSA-qrrc-ww9x-r43g — github.com/docker/docker-ce: upgrade to the fixed version with the command below.

go get github.com/docker/docker-ce@v19.03.11

Details

An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/docker/docker-ce
Introduced in: 0Fixed in: 19.03.11
Fixgo get github.com/docker/docker-ce@v19.03.11

References