VYPR

Weave Net

by Weaveworks

Source repositories

CVEs (2)

  • CVE-2020-26278Jan 20, 2021
    risk 0.00cvss epss 0.00

    Weave Net is open source software which creates a virtual network that connects Docker containers across multiple hosts and enables their automatic discovery. Weave Net before version 2.8.0 has a vulnerability in which can allow an attacker to take over any host in the cluster.…

  • CVE-2020-11091Jun 3, 2020
    risk 0.00cvss epss 0.00

    In Weave Net before version 2.6.3, an attacker able to run a process as root in a container is able to respond to DNS requests from the host and thereby insert themselves as a fake service. In a cluster with an IPv4 internal network, if IPv6 is not totally disabled on the host…