VYPR

Weave Net

by Weave

CVEs (1)

  • CVE-2020-11091MedJun 3, 2020
    risk 0.31cvss 5.8epss 0.01

    In Weave Net before version 2.6.3, an attacker able to run a process as root in a container is able to respond to DNS requests from the host and thereby insert themselves as a fake service. In a cluster with an IPv4 internal network, if IPv6 is not totally disabled on the host…