Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL
CVE-2023-0628

6.1MEDIUM

Key Information:

Vendor
CVE Published:
13 March 2023

What is CVE-2023-0628?

A security flaw exists in Docker Desktop prior to version 4.17.0 that permits attackers to execute arbitrary commands inside Dev Environments containers. This exploitation is achieved by deceiving users into accessing a specially crafted docker-desktop:// URL. Users should ensure they are using the latest version to mitigate this vulnerability.

Affected Version(s)

Docker Desktop Windows 0 < 4.17.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

@suanve
.