Docker Desktop
cpe:2.3:a:docker:desktop:*:*:*:*:*:*:*, +3 more
- < 4.44.3
A vulnerability in Docker Desktop allows local Linux containers to access the Docker Engine API over the default Docker subnet. This issue exists with or without Enhanced Container Isolation (ECI) enabled, and regardless of the 'Expose daemon on tcp://localhost:2375 without TLS' option. The vulnerability enables execution of privileged commands via the Engine API, such as managing containers and images. In some cases, it also allows mounting host drives with user-level privileges.
Exploitation of this vulnerability could lead to unauthorized access and manipulation of Docker containers and images, and in some cases, allow access to the host file system with elevated privileges.
The vulnerability can be reproduced by running a local Linux container on Docker Desktop that accesses the Docker Engine API over the default subnet. This can be done regardless of the Enhanced Container Isolation setting or the 'Expose daemon on tcp://localhost:2375 without TLS' option.
Users can update to Docker Desktop version 4.44.3 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.