Critical Docker Engine Flaw Allows Attackers to Bypass Authorization Plugins

Docker is alerting users about a serious vulnerability in some Docker Engine versions that, in some situations, could let an attacker get around authorization plugins (AuthZ).

The bypass and privilege escalation vulnerability, tracked as CVE-2024-41110, has a maximum severity CVSS score of 10.0.

The Moby Project maintainers issued an alert stating that an attacker may attempt to circumvent security measures by sending an API request with Content-Length set to 0. This would cause the Docker daemon to route the request without the body to the AuthZ plugin, which might authorize it improperly.

According to Docker, the problem is a regression because it was first identified in 2018 and fixed in Docker Engine v18.09.1 in January 2019 read more about Critical Docker Engine Flaw Allows Attackers to Bypass Authorization Plugins.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *