Description
In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed. A targeted network sniffing attack can lead to a disclosure of sensitive information. Only users who have Access Experimental Features enabled and have logged in to a private registry are affected.
Published: 2023-04-06
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update Docker Desktop to version 4.18.0


Vendor Workaround

Disable the Access Experimental Features option from the setting panel 

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-24004 In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed. A targeted network sniffing attack can lead to a disclosure of sensitive information. Only users who have Access Experimental Features enabled and have logged in to a private registry are affected.
History

Mon, 10 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Docker

Published:

Updated: 2025-02-10T20:22:38.457Z

Reserved: 2023-04-03T10:20:15.739Z

Link: CVE-2023-1802

cve-icon Vulnrichment

Updated: 2024-08-02T06:05:26.143Z

cve-icon NVD

Status : Modified

Published: 2023-04-06T09:15:07.030

Modified: 2024-11-21T07:39:56.090

Link: CVE-2023-1802

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses