vipinsun/fabric-token-sdk

CVE-2024-36623 (High) detected in github.com/Docker/Docker-v20.10.7+incompatible

Opened this issue · 0 comments

CVE-2024-36623 - High Severity Vulnerability

Vulnerable Library - github.com/Docker/Docker-v20.10.7+incompatible

Moby Project - a collaborative project for the container ecosystem to assemble container-based systems

Library home page: https://proxy.golang.org/github.com/!docker/!docker/@v/v20.10.7+incompatible.zip

Path to dependency file: /go.mod

Path to vulnerable library: /go.mod

Dependency Hierarchy:

  • github.com/hyperledger-labs/fabric-smart-client (Root Library)
    • github.com/Docker/Docker-v20.10.7+incompatible (Vulnerable Library)

Found in HEAD commit: 999f5d255a183e22a067e6411929924a0bacd65f

Found in base branch: main

Vulnerability Details

moby v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.

Publish Date: 2024-11-29

URL: CVE-2024-36623

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://gist.github.com/1047524396/c192c0159a19bf58a4373b696467dc29

Release Date: 2024-11-29

Fix Resolution: github.com/moby/moby-v25.0.4


Step up your Open Source Security Game with Mend here