logo

You should probably fix this 5-year-old critical Docker vuln fairly sharpish

ID: de561407-d5e8-599f-8783-3669d1099185

STIX ID: report--de561407-d5e8-599f-8783-3669d1099185

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2024-07-25

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Docker Engine is affected by a critical privilege-escalation vulnerability (CVE-2024-41110) where sending an API request with Content-Length: 0 can cause AuthZ plugins to receive no body and mistakenly approve requests; the flaw persisted across versions after an earlier patch and affects Docker Engine releases from 19.03 onward unless updated to the safe versions (v23.0.14 or >v27.1.0). Exploitation is considered low-likelihood because it requires local access or an exposed Docker daemon and AuthZ plugin usage, but the potential impact is high; Docker Desktop will receive a fix in v4.33 and users should upgrade where applicable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.