CVE-2024-29018 affects Moby, a core component of Docker Engine and other container runtimes, allowing containers on "internal" networks to bypass intended isolation. Specifically, it enables DNS requests from internal networks to be forwarded to external nameservers, despite firewall rules designed to prevent such communication. This vulnerability has a CVSS score of 7.5 (High), indicating a network-based attack with low complexity that could lead to high confidentiality impact through data exfiltration via DNS queries. While there is no known active exploitation, exploit code, or KEV listing, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community. Patches are available in Moby releases 26.0.0, 25.0.4, and 23.0.11, and Docker Desktop is not affected.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 23.0.11CPE matchmatch criteria | cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:* | ||
>= 24.0.0, < 25.0.5CPE matchmatch criteria | cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:* | ||
26.0.0CPE matchmatch criteria | cpe:2.3:a:mobyproject:moby:26.0.0:rc1:*:*:*:*:*:* | ||
26.0.0CPE matchmatch criteria | cpe:2.3:a:mobyproject:moby:26.0.0:rc2:*:*:*:*:*:* | ||
26.0.0CPE matchmatch criteria | cpe:2.3:a:mobyproject:moby:26.0.0:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2024-29018
Dec 10, 2024CVE-2024-29018
Oct 8, 2024Moby's external DNS requests from 'internal' networks could lead to data exfiltration
Mar 20, 2024moby: external DNS requests from 'internal' networks could lead to data exfiltration
Mar 20, 2024External DNS requests from 'internal' networks could lead to data exfiltration
Mar 12, 2024