PT-2024-4754 · Docker · Docker Desktop
Äá Minh TuấN
+2
·
Published
2024-04-08
·
Updated
2024-08-07
·
CVE-2024-6222
CVSS v4.0
7.3
High
| Vector | AV:L/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions:
Docker Desktop versions prior to 4.29.0
Description:
The issue is related to insufficient restriction of the communication channel for given endpoints, allowing an attacker who has gained access to the Docker Desktop VM through a container breakout to further escape to the host by passing extensions and dashboard related IPC messages. Exploitation requires the "Allow only extensions distributed through the Docker Marketplace" setting to be disabled.
Recommendations:
For Docker Desktop versions prior to 4.29.0, update to version 4.29.0 or later to fix the issue on MacOS, Linux, and Windows with Hyper-V backend. Additionally, consider enabling the "Allow only extensions distributed through the Docker Marketplace" setting by default, as introduced in Docker Desktop version 4.31.0, to prevent exploitation. As a temporary workaround, consider disabling the extension-manager until a patch is available. Restrict access to the vulnerable IPC messages to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docker Desktop