Docker

Docker Desktop

33 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 25.09.2023 16:15:15
  • Zuletzt bearbeitet 21.11.2024 08:41:12

Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains accessible for a short time window after launching Docker Desktop. The affected functionality is avai...

  • EPSS 0.27%
  • Veröffentlicht 25.09.2023 16:15:13
  • Zuletzt bearbeitet 21.11.2024 07:37:31

In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation (LPE).This issue affects Docker Desktop: before 4.12.0.

  • EPSS 0.24%
  • Veröffentlicht 25.09.2023 16:15:13
  • Zuletzt bearbeitet 21.11.2024 07:37:30

Docker Desktop 4.11.x allows --no-windows-containers flag bypass via IPC response spoofing which may lead to Local Privilege Escalation (LPE).This issue affects Docker Desktop: 4.11.X.

  • EPSS 0.74%
  • Veröffentlicht 25.09.2023 16:15:13
  • Zuletzt bearbeitet 21.11.2024 07:37:30

Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route. This issue affects Docker Desktop: before 4.12.0.

  • EPSS 0.74%
  • Veröffentlicht 25.09.2023 16:15:13
  • Zuletzt bearbeitet 21.11.2024 07:37:30

Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0.

  • EPSS 0.22%
  • Veröffentlicht 13.03.2023 12:15:11
  • Zuletzt bearbeitet 21.11.2024 07:37:30

Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions by setting the Docker host to docker.raw.sock, or npipe:////.pipe/docker_engine_linux on Windows, via the -H (--host) CLI flag or the D...

  • EPSS 0.27%
  • Veröffentlicht 13.03.2023 12:15:10
  • Zuletzt bearbeitet 21.11.2024 07:37:30

Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL.

  • EPSS 0.26%
  • Veröffentlicht 25.05.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:31:27

Docker Desktop 4.3.0 has Incorrect Access Control.

  • EPSS 0.43%
  • Veröffentlicht 25.03.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 06:54:16

Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop i...

  • EPSS 0.93%
  • Veröffentlicht 01.02.2022 06:15:06
  • Zuletzt bearbeitet 21.11.2024 06:49:15

Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files.