First published: Mon Sep 25 2023(Updated: )
Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0.
Credit: security@docker.com security@docker.com
Affected Software | Affected Version | How to fix |
---|---|---|
Docker Docker Desktop | <4.12.0 |
Update to 4.12.0
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0625 is a vulnerability in Docker Desktop before version 4.12.0 that allows remote code execution through a crafted extension description or changelog.
CVE-2023-0625 affects Docker Desktop versions before 4.12.0.
CVE-2023-0625 has a severity rating of 9.8 (critical).
To fix CVE-2023-0625, you should update Docker Desktop to version 4.12.0 or later.
More information about CVE-2023-0625 can be found in the Docker Desktop release notes: https://docs.docker.com/desktop/release-notes/#4120