CVE-2023-0628 MEDIUM

CVE-2023-0628: Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL

Vendor Docker Inc.
Product Docker Desktop
Weakness CWE-77
Published March 13, 2023
Last update February 27, 2025

CVSS base score

6.1/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N

What the vulnerability does

01Description

Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL.

Key dates

02Disclosure timeline

March 13, 2023 CVE published
February 27, 2025 Record updated