Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\pipe\dockerBackend named pipe without verifying the validity of the deserialized .NET objects. This would allow a malicious user in the "docker-users" group (who may not otherwise have administrator access) to escalate to administrator privileges.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Docker for Windows 安全漏洞
Vulnerability Description
Docker for Windows是美国Docker公司的一款基于Windows平台的开源应用容器引擎,它支持在Linux系统上创建一个容器(轻量级虚拟机)并部署和运行应用程序,以及通过配置文件实现应用程序的自动化安装、部署和升级。 基于Windows平台的Docker 18.06.0-ce-rc3-win68之前版本(edge)和18.06.0-ce-win72之前版本(stable)中的HandleRequestAsync方法存在安全漏洞,该漏洞源于程序没有验证反序列化.NET对象的有效性。攻击者可
CVSS Information
N/A
Vulnerability Type
N/A