Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rc4h-xgcc-x9w4

Опубликовано: 25 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains accessible for a short time window after launching Docker Desktop. The affected functionality is available for Docker Business customers only and assumes an environment where users are not granted local root or Administrator privileges.

This issue has been fixed in Docker Desktop 4.23.0.

Affected Docker Desktop versions: from 4.13.0 before 4.23.0.

Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains accessible for a short time window after launching Docker Desktop. The affected functionality is available for Docker Business customers only and assumes an environment where users are not granted local root or Administrator privileges.

This issue has been fixed in Docker Desktop 4.23.0.

Affected Docker Desktop versions: from 4.13.0 before 4.23.0.

EPSS

Процентиль: 3%
0.00015
Низкий

7.1 High

CVSS3

Дефекты

CWE-424
CWE-862

Связанные уязвимости

CVSS3: 7.1
nvd
больше 2 лет назад

Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains accessible for a short time window after launching Docker Desktop. The affected functionality is available for Docker Business customers only and assumes an environment where users are not granted local root or Administrator privileges. This issue has been fixed in Docker Desktop 4.23.0. Affected Docker Desktop versions: from 4.13.0 before 4.23.0.

CVSS3: 7.1
fstec
больше 2 лет назад

Уязвимость платформы для разработки и доставки контейнерных приложений Docker Desktop, связанная с недостатками процедуры авторизации, позволяющая нарушителю получить полные права администратора

EPSS

Процентиль: 3%
0.00015
Низкий

7.1 High

CVSS3

Дефекты

CWE-424
CWE-862