Loading HuntDB...

GHSA-44rc-4548-4794

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed. A targeted network sniffing attack can lead to a disclosure of sensitive information. Only users who have Access Experimental Features enabled and have logged in to a private registry are affected.

Related CVEs

Key Information

GHSA ID
GHSA-44rc-4548-4794
Published
April 6, 2023 9:31 AM
Last Modified
April 17, 2023 6:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 6, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.