Angaben zum Datum
Datum aus dem Text des Eintrags.
Erstmals gesehen am .
Docker Desktop von Docker
Docker Desktop 4.3.2
Docker Desktop 4.3.2 behebt CVE-2021-45449, bei dem in den Versionen 4.3.0 und 4.3.1 sensible Daten wie Zugriffstoken oder Passwort beim Login lokal protokolliert werden konnten, und aktualisiert docker scan auf v0.14.0 mit Erkennung von Log4j 2 CVE-2021-44228 und CVE-2021-45046.
<em class="text-gray-400 italic dark:text-gray-500">2021-12-21</em>
Security
- Fixed CVE-2021-45449 that affects users currently on Docker Desktop version 4.3.0 or 4.3.1.
Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and the user has logged in while on 4.3.0, 4.3.1. Gaining access to this data would require having access to the user’s local files.
Upgrades
Security
Log4j 2 CVE-2021-44228: We have updated the docker scan CLI plugin.
This new version of docker scan is able to detect Log4j 2
CVE-2021-44228 and Log4j 2
CVE-2021-45046
For more information, read the blog post Apache Log4j 2 CVE-2021-44228.