[🐸 Frogbot] Update version of github.com/docker/docker to 27.1.1 #28
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
📦 Vulnerable Dependencies
✍️ Summary
Critical
github.com/docker/docker:v27.0.3+incompatible
[25.0.6]
[26.1.5]
[27.1.1]
🔬 Research Details
Description:
Docker Engine is an open-source containerization platform that allows developers to package applications and their dependencies into portable containers. It includes the Docker Daemon, Docker CLI, and a REST API for managing containers, images, networks, and volumes.
Moby is an open-source project that provides the core components and frameworks for containerization. It serves as the foundation for Docker Engine, offering modular tools like
containerd
andrunc
that can be used to build custom container systems.Authorization plugin (AuthZ) in Docker are used to control access to Docker resources and operations based on user-defined policies. They allow administrators to implement custom authorization logic for various Docker actions, ensuring that only authorized users can perform specific operations.
An attacker could exploit this vulnerability by sending a maliciously crafted API request with the
Content-Length
HTTP header set to0
, causing the Docker daemon to forward the request without a body to the AuthZ plugin. In some cases, the plugin could approve the request and if it does, it could potentially allow unauthorized actions.🐸 JFrog Frogbot