Docker修補電腦版應用程式RCE漏洞
支付動態 · 2024-09-16

9月12日Docker修補Docker Desktop兩項漏洞CVE-2024-8695、CVE-2024-8696,並指出這些漏洞一旦被觸發,攻擊者就有機會遠端執行任意程式碼

近期Docker發布電腦版應用程式Docker Desktop更新4.34.2版,修補2項高風險層級的漏洞CVE-2024-8695、CVE-2024-8696,攻擊者可濫用惡意延伸套件,而有機會遠端執行任意程式碼(RCE),4.0版CVSS風險評分為9.0、8.9,3.1版CVSS風險則都達到了9.8分的程度。

值得留意的是,這項漏洞影響所有版本Docker Desktop,涵蓋Windows、Windows on Arm、Intel版Mac、M系列晶片Mac,以及Debian、Arch等環境執行的Docker Desktop,都存在這項漏洞。

對於這些漏洞發生的原因,資安新聞網站Cybersecurity News指出弱點發生在於該應用程式處理延伸套件的資訊,例如:套件說明、版本更新記錄、發布的URL,攻擊者一旦在延伸套件的相關欄位輸入有問題的內容,就有機會愚弄Docker Desktop,而能在受害電腦執行任意程式碼。

熱門文章
Vietnam's tightening online gaming policy creates new market opportunities
Southeast Asia
PropellerAds Shared a New iGaming Case Study: 97,674 Installs and 12,701 Deposits in 3 Months
Marketing
Online gambling, crypto pose ongoing money laundering risks in Philippines, analyst says
Southeast Asia
Vietnam’s Controlled Gaming Shift Gains Ground, But Domestic Demand Still Lags
Southeast Asia
GAT Expo Puerto Rico Will Pulse with the New Era of Gaming in the Caribbean
Marketing
Kazakhstan plans to penalise online casino promotions
Regulation
HUIDU Invites You to Booth T70 at iGB L!VE 2026 — Let’s Ignite London This July!
HUIDU Focus
1spin4win releases unique slot Don Catleone Hold and Win featuring gangster cats
Online Game
Indiana online casino bill stalls in House committee
Regulation
Gaming & Technology Expo Makes a Powerful Entrance in CDMX
Marketing
Super PAC Raises $48 Million: Sports Betting Forces Ramp Up Political Push
Regulation
Brazil Proposes Raising Gambling Tax Rate to 24%, With Revenue Allocated to Social Security and Healthcare
Regulation
Full House at GAT Expo Cartagena 2026 Academic Agenda
Online Game
Institutional Academy that exceeded expectations marked the opening of GAT CDMX
Online Game
1spin4win grows its Latin American presence by partnering with Fortuna Juegos
Online Game
首頁
遊戲
合作
發現
我的