PT-2023-21567 · Docker · Play With Docker
Cokebeer
·
Published
2023-03-16
·
Updated
2023-03-23
·
CVE-2023-28109
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Play With Docker versions 0.0.2 and prior
Description
Play With Docker is a browser-based Docker playground. The issue arises from incorrect CORS configuration, allowing an attacker to bypass the CORS policy by setting the origin header in an HTTP request to a malicious domain, such as
evil-play-with-docker.com, which would then be echoed in the response header, successfully retrieving basic user information.Recommendations
For versions 0.0.2 and prior, upgrade to the latest version to fix the issue. As a temporary workaround, consider restricting access to the
play-with-docker.com domain to minimize the risk of exploitation. There are no known workarounds other than upgrading to the latest version.Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Play With Docker