First published: Thu Sep 12 2024(Updated: )
A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2.
Credit: security@docker.com
Affected Software | Affected Version | How to fix |
---|---|---|
Docker | <4.34.2 |
Update Docker Desktop to 4.34.2 or a later version
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8695 is classified as a high severity remote code execution vulnerability.
To fix CVE-2024-8695, update Docker Desktop to version 4.34.2 or later.
CVE-2024-8695 can allow an attacker to execute arbitrary code on the host system via a malicious Docker extension.
Users of Docker Desktop versions prior to 4.34.2 are affected by CVE-2024-8695.
Yes, CVE-2024-8695 can be exploited remotely through malicious Docker extensions.