PT-2026-79743 · Unknown · Docker-Socket-Proxy
CVSS v4.0
8.3
High
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
docker-socket-proxy versions prior to 0.5.1
Description
Insufficient access control granularity occurs when the
CONTAINERS environment variable is set, failing to properly gate read endpoints within the /containers Docker API namespace. This allows attackers to use GET requests to the endpoints '/containers/{id}/archive', '/containers/{id}/export', '/containers/{id}/logs', and '/containers/{id}/top' to read arbitrary files and download entire container filesystems as tar archives.Recommendations
Update docker-socket-proxy to version 0.5.1 or later.
Restrict the use of the
CONTAINERS environment variable to minimize the risk of unauthorized access to container data.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docker-Socket-Proxy