PT-2023-2594 · Docker · Docker Desktop For Windows
Published
2023-04-27
·
Updated
2025-01-31
·
CVE-2022-34292
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Docker Desktop for Windows versions prior to 4.6.0
Description
The issue is related to a symlink attack on the hyperv/create dockerBackendV2 API, allowing attackers to overwrite any file by controlling the
DataFolder parameter for DockerDesktop.vhdx. This can lead to unauthorized access, modification, or deletion of data. The vulnerability is associated with errors in handling symbolic links with the DataFolder parameter.Recommendations
For Docker Desktop for Windows versions prior to 4.6.0, update to version 4.6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the
DataFolder parameter in the affected API endpoint until a patch is available. Avoid using the DataFolder parameter in the hyperv/create dockerBackendV2 API until the issue is resolved.Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Docker Desktop For Windows