PT-2023-5447 · Docker · Docker Desktop
M. Haunschmid
·
Publicado
2023-09-25
·
Atualizado
2023-09-26
·
CVE-2023-5166
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Docker Desktop versions prior to 4.23.0
Description
The issue affects Docker Desktop and is related to the disclosure of protected information. It allows a remote attacker to obtain an access token using a specially crafted extension icon URL.
Recommendations
For Docker Desktop versions prior to 4.23.0, update to version 4.23.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of crafted extension icon URLs to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Docker Desktop