CVE-2023-0628 – Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL
https://notcve.org/view.php?id=CVE-2023-0628
Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL. • https://docs.docker.com/desktop/release-notes/#4170 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
CVE-2022-34883 – OS Command Injection Vulnerability in RAID Manager Storage Replication Adapter
https://notcve.org/view.php?id=CVE-2022-34883
OS Command Injection vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users to execute arbitrary OS commands. This issue affects: Hitachi RAID Manager Storage Replication Adapter 02.01.04 versions prior to 02.03.02 on Windows; 02.05.00 versions prior to 02.05.01 on Windows and Docker. Una vulnerabilidad de inyección de comandos del Sistema Operativo en Hitachi RAID Manager Storage Replication Adapter permite a usuarios remotos autenticados ejecutar comandos arbitrarios del Sistema Operativo. Este problema afecta a: Hitachi RAID Manager Storage Replication Adapter 02.01.04 versiones anteriores a 02.03.02 en Windows; 02.05.00 versiones anteriores a 02.05.01 en Windows y Docker. • https://www.hitachi.com/products/it/storage-solutions/sec_info/2022/2022_307.html • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2022-34882 – Information Exposure Vulnerability in RAID Manager Storage Replication Adapter
https://notcve.org/view.php?id=CVE-2022-34882
Information Exposure Through an Error Message vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users to gain sensitive information. This issue affects: Hitachi RAID Manager Storage Replication Adapter 02.01.04 versions prior to 02.03.02 on Windows; 02.05.00 versions prior to 02.05.01 on Windows and Docker. Una vulnerabilidad de Exposición de Información Mediante Mensajes de Error en Hitachi RAID Manager Storage Replication Adapter permite a usuarios remotos autenticados conseguir información confidencial. Este problema afecta a: Hitachi RAID Manager Storage Replication Adapter 02.01.04 versiones anteriores a 02.03.02 en Windows; 02.05.00 versiones anteriores a 02.05.01 en Windows y Docker. • https://www.hitachi.com/products/it/storage-solutions/sec_info/2022/2022_307.html • CWE-209: Generation of Error Message Containing Sensitive Information •
CVE-2021-34079
https://notcve.org/view.php?id=CVE-2021-34079
OS Command injection vulnerability in Mintzo Docker-Tester through 1.2.1 allows attackers to execute arbitrary commands via shell metacharacters in the 'ports' entry of a crafted docker-compose.yml file. Una vulnerabilidad de inyección de comandos del Sistema Operativo en Mintzo Docker-Tester versiones hasta 1.2.1, permite a atacantes ejecutar comandos arbitrarios por medio de meta caracteres de shell en la entrada "ports" de un archivo docker-compose.yml diseñado • https://advisory.checkmarx.net/advisory/CX-2021-4786 https://www.npmjs.com/package/docker-tester • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2021-44719
https://notcve.org/view.php?id=CVE-2021-44719
Docker Desktop 4.3.0 has Incorrect Access Control. Docker Desktop versión 4.3.0, presenta un Control de Acceso Incorrecto • https://docs.docker.com/desktop/mac/release-notes https://docs.docker.com/desktop/release-notes/#security-2 https://docs.docker.com/desktop/windows/release-notes •