Description
Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL.
This issue affects Docker Desktop: before 4.23.0.
This issue affects Docker Desktop: before 4.23.0.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update Docker Desktop to 4.23.0
Vendor Workaround
Disable extensions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57503 | Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desktop: before 4.23.0. |
References
| Link | Providers |
|---|---|
| https://docs.docker.com/desktop/release-notes/#4230 |
|
History
Tue, 24 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2024-09-24T15:54:17.938Z
Reserved: 2023-09-25T14:05:47.327Z
Link: CVE-2023-5166
Updated: 2024-08-02T07:52:07.432Z
Status : Modified
Published: 2023-09-25T16:15:15.857
Modified: 2024-11-21T08:41:13.043
Link: CVE-2023-5166
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD