PT-2024-4755 · Docker · Docker Desktop
Hashim Jawad
+1
·
Published
2024-05-05
·
Updated
2025-05-21
·
CVE-2024-5652
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions:
Docker Desktop versions prior to 4.31.0
Description:
The issue is related to a configuration flaw in the exec-path Docker daemon config option, allowing a user in the docker-users group to cause a Windows Denial-of-Service in Windows containers mode. This is due to inadequate access control. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited. The vulnerability can be exploited through the
exec-path Docker daemon config option, which is a part of the Docker Desktop platform for developing and delivering containerized applications.Recommendations:
For Docker Desktop versions prior to 4.31.0, update to version 4.31.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the
exec-path Docker daemon config option to minimize the risk of exploitation.Fix
DoS
Resource Exhaustion
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Docker Desktop