An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.
No PoCs from references.
- https://github.com/43622283/awesome-cloud-native-security
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/ARPSyndicate/cvemon
- https://github.com/Metarget/awesome-cloud-native-security
- https://github.com/arax-zaeimi/Docker-Container-CVE-2020-13401
- https://github.com/atesemre/awesome-cloud-native-security
- https://github.com/neargle/re0-kubernetes-sec-archive
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/reni2study/Cloud-Native-Security2
- https://github.com/soosmile/POC