PT-2024-39183 · Docker · Docker Desktop
Cure53
·
Published
2024-09-12
·
Updated
2024-10-20
·
CVE-2024-8696
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Docker Desktop versions prior to 4.34.2
Description:
A remote code execution (RCE) vulnerability exists via crafted extension
publisher-url/additional-urls that could be abused by a malicious extension. This issue can be exploited to execute code remotely.Recommendations:
For Docker Desktop versions prior to 4.34.2, update to version 4.34.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of extensions or disabling the
publisher-url and additional-urls features until a patch is applied.Fix
RCE
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Docker Desktop