logo

Docker fixes critical 5-year old authentication bypass flaw

ID: d23f9a20-4cbd-5176-ad11-985660966f6e

STIX ID: report--d23f9a20-4cbd-5176-ad11-985660966f6e

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-07-24

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Docker released patches for CVE-2024-41110, a critical (CVSS 10.0) authorization bypass in Docker Engine caused by a regression that forwards API requests with Content-Length: 0 to AuthZ plugins without the request body, potentially allowing unauthorized actions and privilege escalation for environments using authorization plugins; multiple supported Engine versions are affected and updates are available, with mitigations including upgrading to patched releases, disabling AuthZ plugins, and restricting Docker API access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.