CVE-2021-43565 (High) detected in github.com/docker/cli-v20.10.11, github.com/docker/docker-v20.10.9 - autoclosed #20
Labels
security vulnerability
Security vulnerability detected by WhiteSource
CVE-2021-43565 - High Severity Vulnerability
Vulnerable Libraries - github.com/docker/cli-v20.10.11, github.com/docker/docker-v20.10.9
github.com/docker/cli-v20.10.11
The Docker CLI
Dependency Hierarchy:
github.com/docker/docker-v20.10.9
Moby Project - a collaborative project for the container ecosystem to assemble container-based systems
Dependency Hierarchy:
Found in HEAD commit: c8980a5bef352bb4b9477331dcc940aca400e10b
Found in base branch: main
Vulnerability Details
There's an input validation flaw in golang.org/x/crypto's readCipherPacket() function. An unauthenticated attacker who sends an empty plaintext packet to a program linked with golang.org/x/crypto/ssh could cause a panic, potentially leading to denial of service.
Publish Date: 2021-11-10
URL: CVE-2021-43565
CVSS 3 Score Details (7.5)
Base Score Metrics:
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: