CVE-2023-0628 Information

Description

Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL.

Reference

https://docs.docker.com/desktop/release-notes/#4170

Share on: