QID 379078
Date Published: 2023-12-06
QID 379078: Docker Desktop Access Token Theft Vulnerability (4230)
Docker is a set of platform as a service product that uses OS-level virtualization to deliver software in packages called containers.
CVE-2023-5166: Docker Desktop allows Access Token theft via a crafted extension icon URL.
Affected Versions:
Docker Desktop before version 4.23.0
QID Detection Logic:
It checks for vulnerable versions of Docker Desktop
Successful exploitation of this vulnerability allows attackers to get Access Tokens via a crafted extension icon URL.
Solution
Customers are advised to upgrade to Docker Desktop version 4.23.0 or later. Please refer to Docker Desktop 4230 for further information.
Vendor References
- Docker Desktop -
docs.docker.com/desktop/release-notes/#4230
CVEs related to QID 379078
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Docker Desktop 4.23.0 |
|