Vulnerabilities > Docker

DATE CVE VULNERABILITY TITLE RISK
2024-07-09 CVE-2024-6222 Unspecified vulnerability in Docker Desktop
In Docker Desktop before v4.29.0, an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passing extensions and dashboard related IPC messages. Docker Desktop v4.29.0 https://docs.docker.com/desktop/release-notes/#4290 fixes the issue on MacOS, Linux and Windows with Hyper-V backend. As exploitation requires "Allow only extensions distributed through the Docker Marketplace" to be disabled, Docker Desktop  v4.31.0 https://docs.docker.com/desktop/release-notes/#4310  additionally changes the default configuration to enable this setting by default.
local
high complexity
docker
7.0
2024-07-09 CVE-2024-5652 Unspecified vulnerability in Docker Desktop
In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker daemon config option in Windows containers mode.
local
low complexity
docker
5.5
2023-11-07 CVE-2023-40453 Unspecified vulnerability in Docker Machine
Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, which might potentially trick an administrator into performing an unsafe action (via escape sequence injection), or might have a data size that causes a denial of service to a bastion node.
network
low complexity
docker
6.5
2023-09-25 CVE-2023-0625 Code Injection vulnerability in Docker Desktop
Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0.
network
low complexity
docker CWE-94
critical
9.8
2023-09-25 CVE-2023-0626 Code Injection vulnerability in Docker Desktop
Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route. This issue affects Docker Desktop: before 4.12.0.
network
low complexity
docker CWE-94
critical
9.8
2023-09-25 CVE-2023-0627 Unspecified vulnerability in Docker Desktop 4.11.0/4.11.1
Docker Desktop 4.11.x allows --no-windows-containers flag bypass via IPC response spoofing which may lead to Local Privilege Escalation (LPE).This issue affects Docker Desktop: 4.11.X.
local
low complexity
docker
7.8
2023-09-25 CVE-2023-0633 Argument Injection or Modification vulnerability in Docker Desktop
In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation (LPE).This issue affects Docker Desktop: before 4.12.0.
local
low complexity
docker CWE-88
7.8
2023-09-25 CVE-2023-5165 Missing Authorization vulnerability in Docker Desktop
Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains accessible for a short time window after launching Docker Desktop.
local
low complexity
docker CWE-862
8.8
2023-09-25 CVE-2023-5166 Unspecified vulnerability in Docker Desktop
Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desktop: before 4.23.0.
network
low complexity
docker
6.5
2023-04-27 CVE-2022-31647 Link Following vulnerability in Docker Desktop
Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFolder parameter, a different vulnerability than CVE-2022-26659.
local
low complexity
docker CWE-59
7.1