QID 379082
Date Published: 2024-02-22
QID 379082: Docker Desktop Sensitive Information Disclosure Vulnerability
Docker is a set of platform as a service products that uses OS-level virtualization to deliver software in packages called containers.
CVE-2021-45449: Docker Desktop has a bug that may log sensitive information (access token or password) on the user's machine during login.
Affected Versions:
Docker Desktop version 4.3.0 and 4.3.1
QID Detection Logic:
It checks for vulnerable versions of Docker Desktop by checking its file version on Microsoft Windows.
Successful exploitation of this vulnerability allows attackers to log sensitive information like access token or password.
Solution
Customers are advised to upgrade to latest Docker Desktop version. Please refer to Docker Desktop for further information.
Vendor References
- Docker Desktop -
docs.docker.com/desktop/windows/release-notes/
CVEs related to QID 379082
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Docker Desktop |
|