QID 379080

Date Published: 2023-12-06

QID 379080: Docker Desktop Bypass Enhanced Container Isolation (ECI) Vulnerability (4230)

Docker is a set of platform as a service product that uses OS-level virtualization to deliver software in packages called containers.

CVE-2023-5165: Docker Desktop allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains accessible for a short time window after launching Docker Desktop. The affected functionality is available for Docker Business customers only and assumes an environment where users are not granted local root or Administrator privileges.

Affected Versions:
Docker Desktop version from 4.13.0 before 4.23.0

QID Detection Logic:
It checks for vulnerable versions of Docker Desktop

Successful exploitation of this vulnerability allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to Docker Desktop version 4.23.0 or later. Please refer to Docker Desktop 4230 for further information.
    Vendor References

    CVEs related to QID 379080

    Software Advisories
    Advisory ID Software Component Link
    Docker Desktop 4.23.0 URL Logo docs.docker.com/desktop/release-notes/#4230