PT-2024-6924 · Docker · Docker Desktop

Cure53

·

Published

2024-10-09

·

Updated

2024-10-16

·

CVE-2024-9348

CVSS v4.0

8.9

High

VectorAV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Docker Desktop versions prior to 4.34.3
Description The issue is related to a lack of output encoding or sanitization mechanism in Docker Desktop, which can be exploited by a remote attacker to execute arbitrary code by injecting it through an unsanitized GitHub source link in the Build view. This allows for remote code execution.
Recommendations For Docker Desktop versions prior to 4.34.3, update to version 4.34.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the Build view or avoiding the use of GitHub source links until the update is applied.

Fix

Improper Encoding or Escaping of Output

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-08147
CVE-2024-9348

Affected Products

Docker Desktop