Description
In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed. A targeted network sniffing attack can lead to a disclosure of sensitive information. Only users who have Access Experimental Features enabled and have logged in to a private registry are affected.
References (2)
Core 2
Core References
Release Notes release-notes
https://docs.docker.com/desktop/release-notes/#4180
Exploit issue-tracking
https://github.com/docker/for-win/issues/13344
Scores
CVSS v3
5.9
EPSS
0.0055
EPSS Percentile
41.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-319
Status
published
Products (2)
docker/desktop
4.17.0
docker/desktop
4.17.1
Published
Apr 06, 2023
Tracked Since
Feb 18, 2026