QID 379269

Date Published: 2024-03-04

QID 379269: Docker Desktop Artifactory Integration HTTPS Fallback Vulnerability (CVE-2023-1802)

Docker is a set of the platform as a service product that uses OS-level virtualization to deliver software in packages called containers.

In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed. A targeted network sniffing attack can lead to a disclosure of sensitive information. Only users who have Access Experimental Features enabled and have logged in to a private registry are affected.

Affected Versions:
Docker Desktop Community Edition 4.17.0 and 4.17.1

QID Detection Logic:
It checks for vulnerable versions of Docker Desktop

Successful exploitation of this vulnerability can expose registry credentials through Artifactory Integration's HTTPS fallback, impacting users with Access experimental features enabled.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Customers are advised to upgrade to the latest version and can be downloaded from Docker Desktop 4180.
    Vendor References

    CVEs related to QID 379269

    Software Advisories
    Advisory ID Software Component Link
    Docker Desktop 4.18.0 URL Logo docs.docker.com/desktop/release-notes/#4180