QID 378631
Date Published: 2023-07-19
QID 378631: Docker Engine Git Vulnerability
Docker Engine enables containerized applications to run anywhere consistently on any infrastructure.
Affected Versions:
Docker Engine before 20.10.20
NOTE: This vulnerability is only affected to Windows.
QID Detection Logic(Authenticated):
Vulnerable versions of docker from ImagePath using the registry "HKLM\SYSTEM\ControlSet001\Services\docker".
Successful exploitation can cause maliciously crafted Git repository, when used as a build context, to copy arbitrary filesystem.
Solution
Customers are advised to upgrade to Docker Engine 20.10.20 or later versions to remediate this vulnerability.
Vendor References
- CVE-2022-39253 -
docs.docker.com/engine/release-notes/20.10/
CVEs related to QID 378631
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-39253 |
|