QID 379080
Date Published: 2023-12-06
QID 379080: Docker Desktop Bypass Enhanced Container Isolation (ECI) Vulnerability (4230)
Docker is a set of platform as a service product that uses OS-level virtualization to deliver software in packages called containers.
CVE-2023-5165: Docker Desktop allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains accessible for a short time window after launching Docker Desktop. The affected functionality is available for Docker Business customers only and assumes an environment where users are not granted local root or Administrator privileges.
Affected Versions:
Docker Desktop version from 4.13.0 before 4.23.0
QID Detection Logic:
It checks for vulnerable versions of Docker Desktop
Successful exploitation of this vulnerability allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell.
- Docker Desktop -
docs.docker.com/desktop/release-notes/#4230
CVEs related to QID 379080
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Docker Desktop 4.23.0 |
|