CVE-2023-40453

Improper Neutralization of Escape, Meta, or Control Sequences in go/github.com/docker/machine

Identifiers

CVE-2023-40453

Package Slug

go/github.com/docker/machine

Vulnerability

Improper Neutralization of Escape, Meta, or Control Sequences

Description

Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, which might potentially trick an administrator into performing an unsafe action (via escape sequence injection), or might have a data size that causes a denial of service to a bastion node. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Affected Versions

All versions up to 0.16.2

Solution

Unfortunately, there is no solution available yet.

Last Modified

2023-11-16

source