An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13401
Reference (s):
- https://github.com/docker/docker-ce/releases/tag/v19.03.11
- https://security.netapp.com/advisory/ntap-20200717-0002/
- DEBIAN:DSA-4716
- URL: https://www.debian.org/security/2020/dsa-4716
- FEDORA:FEDORA-2020-5ba8c2d9d5

