CVE-2024-8696·Docker vulnerability
A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2.
- Severity
- critical
- Software
- Docker
- Fixed in
- 4.34.2
- Published
- 2024-09-12
Affected versions
Until: 4.34.2
Fixed in: 4.34.2
How to fix this CVE
Update Docker Desktop to version 4.34.2 or later to patch a critical remote code execution flaw that could be triggered through malicious extension configurations. This vulnerability allows attackers to execute arbitrary code by crafting malicious publisher URLs or additional URLs within Docker extensions, making immediate patching essential for all Docker Desktop users.
sudo dnf update docker-ce docker-ce-cliDefensia detects this vulnerability
How to check if you are affected
- Run 'docker --version' to confirm the currently installed Docker version and verify it is 4.34.2 or later
- Check for suspicious extension installations with 'docker extension ls' and review any unfamiliar or recently-added extensions
- Examine Docker Desktop logs at ~/.docker/desktop/log.txt (macOS/Linux) or %APPDATA%\Docker\log.txt (Windows) for errors related to extension URL parsing or unexpected network calls
- After applying the patch, re-run 'docker --version' and verify the output shows version 4.34.2 or higher to confirm the remediation was successful
FAQ
What is CVE-2024-8696?
This is a critical remote code execution vulnerability in Docker Desktop that allows attackers to execute arbitrary code by embedding malicious publisher URLs or additional URLs within Docker extensions. An attacker could craft a malicious extension that triggers code execution when loaded or interacted with.
Is CVE-2024-8696 being actively exploited?
There is no evidence of active exploitation in the wild at this time, and no public exploits have been released. However, the critical CVSS score of 9.8 warrants immediate patching regardless of current threat activity.
What versions of Docker are affected by CVE-2024-8696?
All versions of Docker Desktop before 4.34.2 are vulnerable. The vulnerability was patched in Docker Desktop 4.34.2 and later.
How do I check if my server is vulnerable to CVE-2024-8696?
Run 'docker --version' and compare the version number to 4.34.2. If your version is lower than 4.34.2, your system is vulnerable and requires immediate updating.
Does Defensia detect CVE-2024-8696?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker is installed on a monitored server, CVE-2024-8696 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-8696. Free for 1 server.
Get started free