PT-2023-13527 · Docker · Docker Desktop For Windows

CVE-2022-37326

·

Publicado

2023-04-27

·

Atualizado

2025-01-31

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Docker Desktop for Windows versions prior to 4.6.0
Description The issue allows attackers to delete or create any file through the "dockerBackendV2 windowscontainers/start" API endpoint by controlling the pidfile field inside the DaemonJSON field in the WindowsContainerStartRequest class. This can indirectly lead to privilege escalation.
Recommendations For versions prior to 4.6.0, update to version 4.6.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the "dockerBackendV2 windowscontainers/start" API endpoint until a patch is available. Avoid using the pidfile field in the DaemonJSON field of the WindowsContainerStartRequest class in the affected API endpoint until the issue is resolved.

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-37326

Produtos afetados

Docker Desktop For Windows