VYPR
Medium severity5.9NVD Advisory· Published Apr 6, 2023· Updated Jun 17, 2026

CVE-2023-1802

CVE-2023-1802

Description

In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed. A targeted network sniffing attack can lead to a disclosure of sensitive information. Only users who have Access Experimental Features enabled and have logged in to a private registry are affected.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Docker/Desktop4 versions
    cpe:2.3:a:docker:desktop:4.17.0:*:*:*:*:windows:*:*+ 3 more
    • cpe:2.3:a:docker:desktop:4.17.0:*:*:*:*:windows:*:*
    • cpe:2.3:a:docker:desktop:4.17.1:*:*:*:*:windows:*:*
    • (no CPE)range: 4.17.x
    • (no CPE)range: 4.17.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.