CVE-2024-6222
HIGHDescription
In Docker Desktop before v4.29.0, an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by passing extensions and dashboard related IPC messages. Docker Desktop v4.29.0 https://docs.docker.com/desktop/release-notes/#4290 fixes the issue on MacOS, Linux and Windows with Hyper-V backend. As exploitation requires "Allow only extensions distributed through the Docker Marketplace" to be disabled, Docker Desktop v4.31.0 https://docs.docker.com/desktop/release-notes/#4310 additionally changes the default configuration to enable this setting by default.
Is your site exposed to CVE-2024-6222?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| docker | desktop |
| apple | macos |
| linux | linux_kernel |
| microsoft | windows |
References
Frequently Asked Questions
What is CVE-2024-6222? +
How severe is CVE-2024-6222? +
What products are affected by CVE-2024-6222? +
How do I check if I'm vulnerable to CVE-2024-6222? +
Related Vulnerabilities
An improper access control vulnerability in an internal API service on WatchGuard Access Points allows an unauthenticated attacker with network …
FTP Passive Data Connection Not Bound to the Authenticated Control Peer
OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client …
mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, …
Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service …
Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by …