First published: Thu Sep 12 2024(Updated: )
A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2.
Credit: security@docker.com
Affected Software | Affected Version | How to fix |
---|---|---|
Docker | <4.34.2 |
Update Docker Desktop to 4.34.2 or a later version
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8696 is classified as a critical remote code execution vulnerability.
To fix CVE-2024-8696, upgrade Docker Desktop to version 4.34.2 or later.
CVE-2024-8696 is caused by a vulnerability in how Docker Desktop handles crafted extension publisher-url/additional-urls.
Docker Desktop versions prior to 4.34.2 are affected by CVE-2024-8696.
Yes, CVE-2024-8696 can lead to remote code execution that may result in data loss.