QID 378908

Date Published: 2023-10-04

QID 378908: Docker Desktop Remote Code Execution (RCE) Vulnerability (4120)

Docker is a set of the platform as a service product that uses OS-level virtualization to deliver software in packages called containers.

CVE-2023-0626: Docker Desktop is vulnerable to RCE via query parameters in the message-box route in the Electron client.
CVE-2023-0625: Docker Desktop is vulnerable to RCE via extension description/changelog which could be abused by a malicious extension.

Affected Versions:
Docker Desktop Community Edition before 4.12.0

QID Detection Logic:
It checks for vulnerable versions of Docker Desktop

Successful exploitation of these vulnerabilities may allow an attacker to execute arbitrary command on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to Docker Desktop version 4.12.0 or later. Please refer to Docker Desktop Release Notes for version 4.12.0 for further information.
    Vendor References

    CVEs related to QID 378908

    Software Advisories
    Advisory ID Software Component Link
    Docker Desktop Release Notes URL Logo docs.docker.com/desktop/release-notes/#4120