PT-2023-2594 · Docker · Docker Desktop For Windows
Publicado
2023-04-27
·
Atualizado
2025-01-31
·
CVE-2022-34292
CVSS v3.1
7.1
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Docker Desktop for Windows versions prior to 4.6.0
Description
The issue is related to a symlink attack on the hyperv/create dockerBackendV2 API, allowing attackers to overwrite any file by controlling the
DataFolder parameter for DockerDesktop.vhdx. This can lead to unauthorized access, modification, or deletion of data. The vulnerability is associated with errors in handling symbolic links with the DataFolder parameter.Recommendations
For Docker Desktop for Windows versions prior to 4.6.0, update to version 4.6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the
DataFolder parameter in the affected API endpoint until a patch is available. Avoid using the DataFolder parameter in the hyperv/create dockerBackendV2 API until the issue is resolved.Correção
Link Following
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Docker Desktop For Windows