Show filters
95 Total Results
Displaying 21-30 of 95
Sort by:
Attacker Value
Unknown

CVE-2023-0628

Disclosure Date: March 13, 2023 (last updated October 08, 2023)
Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL.
Attacker Value
Unknown

CVE-2021-34079

Disclosure Date: June 02, 2022 (last updated October 07, 2023)
OS Command injection vulnerability in Mintzo Docker-Tester through 1.2.1 allows attackers to execute arbitrary commands via shell metacharacters in the 'ports' entry of a crafted docker-compose.yml file.
Attacker Value
Unknown

CVE-2021-44719

Disclosure Date: May 25, 2022 (last updated October 07, 2023)
Docker Desktop 4.3.0 has Incorrect Access Control.
Attacker Value
Unknown

CVE-2022-26659

Disclosure Date: March 25, 2022 (last updated October 07, 2023)
Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop installer, when run elevated, will write its log files to a location not writable by non-administrator users.
Attacker Value
Unknown

CVE-2022-25365

Disclosure Date: February 19, 2022 (last updated October 07, 2023)
Docker Desktop before 4.5.1 on Windows allows attackers to move arbitrary files. NOTE: this issue exists because of an incomplete fix for CVE-2022-23774.
Attacker Value
Unknown

CVE-2022-23774

Disclosure Date: February 01, 2022 (last updated October 07, 2023)
Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files.
Attacker Value
Unknown

CVE-2021-45449

Disclosure Date: January 12, 2022 (last updated October 07, 2023)
Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and the user has logged in while on 4.3.0, 4.3.1. Gaining access to this data would require having access to the user’s local files.
Attacker Value
Unknown

CVE-2021-41092

Disclosure Date: October 04, 2021 (last updated November 08, 2023)
Docker CLI is the command line interface for the docker container runtime. A bug was found in the Docker CLI where running `docker login my-private-registry.example.com` with a misconfigured configuration file (typically `~/.docker/config.json`) listing a `credsStore` or `credHelpers` that could not be executed would result in any provided credentials being sent to `registry-1.docker.io` rather than the intended private registry. This bug has been fixed in Docker CLI 20.10.9. Users should update to this version as soon as possible. For users unable to update ensure that any configured credsStore or credHelpers entries in the configuration file reference an installed credential helper that is executable and on the PATH.
Attacker Value
Unknown

CVE-2021-37841

Disclosure Date: August 12, 2021 (last updated November 28, 2024)
Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows containers, it can lead to a full container compromise in both process isolation and Hyper-V isolation modes. This security issue leads an attacker with low privilege to read, write and possibly even execute code inside the containers.
Attacker Value
Unknown

CVE-2021-27886

Disclosure Date: March 02, 2021 (last updated February 22, 2025)
rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product.