Impact
The flaw lies in Docker Sandboxes’ handling of OAuth token-endpoint hostnames. The system compares hostnames case‑sensitively when deciding whether to mask the provider’s response, while DNS routing treats hostname comparisons case‑insensitively. This mismatch allows an attacker who can execute code within a sandbox to supply a case‑variant hostname that resolves to the real provider endpoint. When the OAuth flow is completed, the access and refresh tokens are returned unmasked to the sandbox and become exposed to the malicious code, effectively leaking the host‑managed credentials.
Affected Systems
The vulnerability affects Docker Sandboxes released prior to version 0.47.0. Any deployment using an unpatched Docker Sandboxes instance is susceptible, especially where untrusted code is allowed to run inside the sandbox environment.
Risk and Exploitability
The CVSS score of 6.7 indicates a moderate impact. EPSS data is unavailable, and the vulnerability is not listed in CISA’s KEV catalog. An attacker would need to run code inside the sandbox – a capability typically granted to a loaded container image or script – and lease a case‑variant hostname to reach the provider. If achieved, the attacker can capture OAuth tokens and gain credential access, but the exploit requires presence of untrusted code within the environment and the ability to construct the credential injection scenario as described by the vendor documentation.
OpenCVE Enrichment