"value":"A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')",
"cweId":"CWE-79"
}
]
},
{
"description":[
{
"lang":"eng",
"value":"CWE-94 Improper Control of Generation of Code ('Code Injection')",
"value":"Configure a <a target=\"_blank\" rel=\"nofollow\" href=\"https://docs.docker.com/extensions/private-marketplace/\">private marketplace</a> with a curated list of trusted extensions (for Docker Business customers only)"
}
],
"value":"Configure a private marketplace https://docs.docker.com/extensions/private-marketplace/ with a curated list of trusted extensions (for Docker Business customers only)"
}
],
"solution":[
{
"lang":"en",
"supportingMedia":[
{
"base64":false,
"type":"text/html",
"value":"Update Docker Desktop to 4.34.2 or a later version"
}
],
"value":"Update Docker Desktop to 4.34.2 or a later version"