Docker fixes critical 5-year old authentication bypass flaw
ID: d23f9a20-4cbd-5176-ad11-985660966f6e
STIX ID: report--d23f9a20-4cbd-5176-ad11-985660966f6e
Feed Name: Bleeping Computer
Docker released patches for CVE-2024-41110, a critical (CVSS 10.0) authorization bypass in Docker Engine caused by a regression that forwards API requests with Content-Length: 0 to AuthZ plugins without the request body, potentially allowing unauthorized actions and privilege escalation for environments using authorization plugins; multiple supported Engine versions are affected and updates are available, with mitigations including upgrading to patched releases, disabling AuthZ plugins, and restricting Docker API access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
