Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run 'docker login' to force the command.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Docker 权限许可和访问控制问题漏洞
Vulnerability Description
Docker是美国Docker公司的一款开源的应用容器引擎。该产品支持在Linux系统上创建一个容器(轻量级虚拟机)并部署和运行应用程序,以及通过配置文件实现应用程序的自动化安装、部署和升级。 Docker Desktop Community Edition 2.1.0.1之前版本中存在安全漏洞。本地攻击者可通过向%PROGRAMDATA%DockerDesktopversion-bin中放置恶意的docker-credential-wincred.exe文件利用该漏洞获取权限。
CVSS Information
N/A
Vulnerability Type
N/A