Back to Database
Status published
High
CVE-2024-9348
Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view
Vulnerability Description
Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-9348
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Cure53
More from Docker
View All →CVE-2025-9164
Multiple DLL Search Order Hijacking Vulnerabilities in Docker Desktop Installer for Windows
High
8.8
CVE-2025-9074
Docker Desktop allows unauthenticated access to Docker Engine API from containers
Critical
9.3
CVE-2025-6587
Exposure of system environment variables in Docker Desktop diagnostic logs
Medium
5.2
CVE-2025-4095
Registry Access Management (RAM) policies not applied when sign-in enforcement is configured via a configuration profile
Medium
4.3
CVE-2025-3911
Exposure in Docker Desktop logs of environment variables configured for running containers
Medium
5.2
Affected Vendor
Docker
View all reports →Affected Software
Docker Desktop
Vulnerable Versions:
0
Timeline
Official Publish:
October 16th, 2024
Last Modified:
October 17th, 2024
Added to House:
July 22nd, 2026