
Author: Gabriela Georgieva
-
Docker Security Advisory: AuthZ Plugin Bypass Regression in Docker Engine
Certain versions of Docker Engine have a security vulnerability that could allow an attacker to bypass authorization plugins (AuthZ) under specific circumstances. The base likelihood of this being exploited is low. This advisory outlines the issue, identifies the affected versions, and provides remediation steps for impacted users. Problem Docker’s default authorization model is all-or-nothing. Users…
Read now
-
Docker Security Advisory: Multiple Vulnerabilities in runc, BuildKit, and Moby
February 1 updates: A patch (4.27.1) is now available for Docker Desktop. January 31 updates: Patches for runc, BuildKit, and Moby (Docker Engine) are now available. Updates have been rolled out to Docker Build Cloud builders. We at Docker prioritize the security and integrity of our software and the trust of our users. Security researchers…
Read now