An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
A repository publisher without delete permission may modify protected package content under specific conditions.
Hunt.io researchers analyzed two open directories recovered through Attack Capture system and reconstructed the tooling one operator used to find, exploit, and view internet-exposed cameras in Ukraine.
Technical highlights:
A custom FastAPI/Docker project the operator named camview, which wraps the open-source Ingram scanner, brute-forces camera credentials over HTTP and RTSP (3,811 pair dictionary), and transcodes RTSP to MJPEG for browser viewing Ingram targets known camera CVEs: CVE-2017-7921 and CVE-2021-36260 (Hikvision), CVE-2021-33044/33045 (Dahua), CVE-2020-25078 (D-Link), CVE-2020-25169 (Reolink) The operator's logs recorded live viewing sessions from 58 Ukrainian cameras, with session lengths, frame counts, and frame rates A proxy script authenticated to a compromised OpenCart admin panel and relayed the operator's traffic through the victim network A second, separately operated directory was linked only by the same Ingram scanner. It chained TP-Link Archer CVEs (CVE-2024-53375, CVE-2024-57049) and MikroTik API brute-forcing to turn edge devices into SOCKS5 proxies reporting to a chisel listener on port 4444
No state attribution. Full analysis, IOCs, and ATT&CK mapping in the writeup
A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate privileges to SYSTEM. During an update, Docker Desktop attempts to delete files and subdirectories under the path C:\ProgramData\Docker\config with high privileges. However, this directory often does not exist by default, and C:\ProgramData\ allows normal users to create new directories. By creating a malicious Docker\config folder structure at this location, an attacker can force the privileged update process to delete or manipulate arbitrary system files, leading to Elevation of Privilege.
A vulnerability exists in Docker Desktop prior to version 4.39.0 that could lead to the unintentional disclosure of sensitive information via application logs. In affected versions, proxy configuration data—potentially including sensitive details—was written to log files in clear text whenever an HTTP GET request was made through a proxy. An attacker with read access to these logs could obtain the proxy information and leverage it for further attacks or unauthorized access. Starting with version 4.39.0, Docker Desktop no longer logs the proxy string, thereby mitigating this risk.
End of life: 4/17/2025, Latest version: 28.0.4
An issue in Docker-proxy v18.09.0 allows attackers to cause a denial of service.
End of life: 5/3/2025, Latest version: 27.5.1
End of life: 1/13/2025, Latest version: 27.4.1
End of life: 1/13/2025, Latest version: 27.4.1
Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.
End of life: 5/19/2025, Latest version: 23.0.18
End of life: 5/19/2025, Latest version: 23.0.18
End of life: 12/9/2024, Latest version: 27.3.1
End of life: 12/9/2024, Latest version: 27.3.1
A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2.
A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2.
End of life: 9/19/2024, Latest version: 27.2.1
End of life: 9/19/2024, Latest version: 27.2.1
End of life: 8/27/2024, Latest version: 27.1.2
End of life: 8/27/2024, Latest version: 27.1.2
End of life: 7/22/2024, Latest version: 27.0.3
End of life: 7/22/2024, Latest version: 27.0.3
End of life: 2/17/2025, Latest version: 26.1.5
End of life: 2/17/2025, Latest version: 26.1.5
End of life: 6/8/2024, Latest version: 26.0.2