QID 379337

Date Published: 2024-02-01

QID 379337: Docker Desktop Runc and BuildKit Vulnerability

Docker is a set of the platform as a service product that uses OS-level virtualization to deliver software in packages called containers.

For more information pease refer to docker-security-advisory.

Affected Versions:
Docker Desktop version prior to 4.27.1

QID Detection Logic:
It checks for vulnerable version of Docker.

Successful exploitation of this vulnerability allows attackers to get Incorrect Access Control.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Customers are advised to upgrade to latest Docker Desktop version. Please refer to Docker Desktop for further information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link