Impact
The flaw in Laradock’s build process permits an adversary to remotely trigger the download of arbitrary code into the workspace Dockerfile without any integrity verification, exposing the system to the execution of malicious payloads.
Affected Systems
The vulnerability affects the Laradock project and its Dockerfiles, specifically versions up to 20.4.; any deployment using those builds is at risk.
Risk and Exploitability
With a CVSS score of 2.3 the severity is low, yet the exploit is publicly available and can be launched remotely with high complexity, making it difficult but technically feasible. The lack of an integrity check elevates the risk of unauthorized code execution, though the vulnerability is not yet listed in CISA’s KEV catalog.
OpenCVE Enrichment