
CVE-2022-26659
https://notcve.org/view.php?id=CVE-2022-26659
25 Mar 2022 — Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop installer, when run elevated, will write its log files to a location not writable by non-administrator users. El instalador de Docker Desktop en Windows en versiones anteriores a 4.6.0, permite a un atacante sobrescribir cualquier archivo escribible por el admini... • https://docs.docker.com/desktop/windows/release-notes • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVE-2022-25365
https://notcve.org/view.php?id=CVE-2022-25365
19 Feb 2022 — Docker Desktop before 4.5.1 on Windows allows attackers to move arbitrary files. NOTE: this issue exists because of an incomplete fix for CVE-2022-23774. Docker Desktop versiones anteriores a 4.5.1 en Windows, permite a atacantes mover archivos arbitrarios. NOTA: este problema se presenta debido a una corrección incompleta de CVE-2022-23774 • https://github.com/followboy1999/CVE-2022-25365 •

CVE-2022-23774 – Docker Desktop Link Following Denial-of-Service Vulnerability
https://notcve.org/view.php?id=CVE-2022-23774
01 Feb 2022 — Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files. Docker Desktop versiones anteriores a 4.4.4 en Windows, permite a atacantes mover archivos arbitrarios This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Docker Desktop. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Docker Desktop Service. By crea... • https://docs.docker.com/docker-for-windows/release-notes •

CVE-2021-45449
https://notcve.org/view.php?id=CVE-2021-45449
12 Jan 2022 — Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and the user has logged in while on 4.3.0, 4.3.1. Gaining access to this data would require having access to the user’s local files. Docker Desktop versiones 4.3.0 y 4.3.1, presenta un bug que puede registrar información confidencial (token de acceso o contraseña) en la máquina del usuario durante... • https://docs.docker.com/desktop/windows/release-notes • CWE-532: Insertion of Sensitive Information into Log File •

CVE-2021-29742
https://notcve.org/view.php?id=CVE-2021-29742
15 Jul 2021 — IBM Security Verify Access Docker 10.0.0 could allow a user to impersonate another user on the system. IBM X-Force ID: 201483. IBM Security Verify Access Docker versión 10.0.0, podría permitir a un usuario hacerse pasar por otro en el sistema. IBM X-Force ID: 201483 • https://exchange.xforce.ibmcloud.com/vulnerabilities/201483 •

CVE-2021-29699
https://notcve.org/view.php?id=CVE-2021-29699
15 Jul 2021 — IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary files with a dangerous file type that could be excuted by an user. IBM X-Force ID: 200600. IBM Security Verify Access Docker versión 10.0.0, podría permitir a un usuario privilegiado remotos cargar archivos arbitrarios con un tipo de archivo peligroso que podría ser ejecutado por un usuario. IBM X-Force ID: 200600 • https://exchange.xforce.ibmcloud.com/vulnerabilities/200600 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2021-20537
https://notcve.org/view.php?id=CVE-2021-20537
15 Jul 2021 — IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID:198918 IBM Security Verify Access Docker versión 10.0.0, contiene credenciales embebidas, como una contraseña o una clave criptográfica, que usa para su propia autenticación de entrada, la comunicación de salida a componentes externos o el cifrado de da... • https://exchange.xforce.ibmcloud.com/vulnerabilities/198918 • CWE-798: Use of Hard-coded Credentials •

CVE-2021-20534
https://notcve.org/view.php?id=CVE-2021-20534
15 Jul 2021 — IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 198814 IBM Security Verify Access... • https://exchange.xforce.ibmcloud.com/vulnerabilities/198814 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2021-20533
https://notcve.org/view.php?id=CVE-2021-20533
15 Jul 2021 — IBM Security Verify Access Docker 10.0.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 198813 IBM Security Verify Access Docker versión 10.0.0, podría permitir a un atacante remoto autenticado ejecutar comandos arbitrarios en el sistema mediante el envío de una petición especialmente diseñada. IBM X-Force ID: 198813 • https://exchange.xforce.ibmcloud.com/vulnerabilities/198813 •

CVE-2021-20524
https://notcve.org/view.php?id=CVE-2021-20524
15 Jul 2021 — IBM Security Verify Access Docker 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198661. IBM Security Verify Access Docker versión 10.0.0, es vulnerable a un ataque de tipo cross-site scripting. Esta vulnerabilidad permite a usuarios insertar código JavaScript arbitrario en la Interfaz de Usuario Web, ... • https://exchange.xforce.ibmcloud.com/vulnerabilities/198661 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •