{"id":"CVE-2023-40453","details":"Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, which might potentially trick an administrator into performing an unsafe action (via escape sequence injection), or might have a data size that causes a denial of service to a bastion node. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.","modified":"2026-07-15T01:49:16.116121008Z","published":"2023-08-14T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/40xxx/CVE-2023-40453.json"},"references":[{"type":"WEB","url":"https://hackerone.com/reports/1916285"},{"type":"WEB","url":"https://vin01.github.io/piptagole/docker/security/gitlab/docker-machine/2023/07/07/docker-machine-attack-surface.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/40xxx/CVE-2023-40453.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40453"},{"type":"PACKAGE","url":"https://github.com/docker/machine/releases"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/docker-archive-public/docker.machine","events":[{"introduced":"0"},{"fixed":"bd45ab13d88c32a3dd701485983354514abc41fa"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.16.2"}],"source":"DESCRIPTION"}}],"versions":["docs-v0.8.2-2016-09-26","docs-v0.8.0-2016-07-28","docs-v0.8.0-rc2-2016-06-23","v0.7.0","v0.7.0-rc3","v0.7.0-rc2","v0.6.0-rc4","v0.6.0-rc3","v0.6.0-rc1","v0.5.4","v0.5.3","v0.5.2","v0.5.1","v0.5.0-rc4","v0.5.0","v0.5.0-rc3","v0.5.0-rc2","v0.5.0-rc1","v0.3.0-rc1","v0.2.0-rc2","v0.2.0-rc1","v0.1.0","v0.1.0-rc5","v0.1.0-rc4","v0.1.0-rc3","v0.1.0-rc2","v0.1.0-rc1","0.0.2","0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-40453.json"}}],"schema_version":"1.7.5"}