Docker Desktop (<4.23.0): Access Token theft via crafted extension icon URL
CVE-2023-5166 Published on September 25, 2023
Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL
Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL.
This issue affects Docker Desktop: before 4.23.0.
Vulnerability Analysis
CVE-2023-5166 is exploitable with network access, requires user interaction and a small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2023-5166 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2023-5166
Want to know whenever a new CVE is published for Docker Desktop? stack.watch will email you.
Affected Versions
Docker Inc. Docker Desktop:- Before 4.23.0 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.