PT-2023-2594 · Docker · Docker Desktop For Windows

Publicado

2023-04-27

·

Atualizado

2025-01-31

·

CVE-2022-34292

CVSS v3.1

7.1

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Docker Desktop for Windows versions prior to 4.6.0
Description The issue is related to a symlink attack on the hyperv/create dockerBackendV2 API, allowing attackers to overwrite any file by controlling the DataFolder parameter for DockerDesktop.vhdx. This can lead to unauthorized access, modification, or deletion of data. The vulnerability is associated with errors in handling symbolic links with the DataFolder parameter.
Recommendations For Docker Desktop for Windows versions prior to 4.6.0, update to version 4.6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the DataFolder parameter in the affected API endpoint until a patch is available. Avoid using the DataFolder parameter in the hyperv/create dockerBackendV2 API until the issue is resolved.

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-02413
CVE-2022-34292

Produtos afetados

Docker Desktop For Windows