First published: Wed Oct 16 2024(Updated: )
Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.
Credit: security@docker.com
Affected Software | Affected Version | How to fix |
---|---|---|
Docker | <4.34.3 |
Update to Docker Desktop 4.34.3 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9348 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2024-9348, upgrade Docker Desktop to version 4.34.3 or later.
The impact of CVE-2024-9348 includes the ability for an attacker to execute arbitrary code on affected systems.
Docker Desktop versions before 4.34.3 are affected by CVE-2024-9348.
Currently, there is no documented workaround for CVE-2024-9348; upgrading to a fixed version is the recommended action.