<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/critical-docker-engine-flaw-allows-attackers-to-bypass-authorization-plugins-ssgh6g2ei" -->

---
title: Critical Docker Engine Flaw Allows Attackers to Bypass...
description: Docker has re-patched a critical authorization bypass vulnerability (CVE-2024-41110) affecting specific versions of Docker Engine and Docker Desktop. The flaw,...
canonical: https://daily.dev/posts/critical-docker-engine-flaw-allows-attackers-to-bypass-authorization-plugins-ssgh6g2ei
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Critical Docker Engine Flaw Allows Attackers to Bypass Authorization Plugins | daily.dev
og:description: Docker has re-patched a critical authorization bypass vulnerability (CVE-2024-41110) affecting specific versions of Docker Engine and Docker Desktop. The flaw,...
og:url: https://daily.dev/posts/critical-docker-engine-flaw-allows-attackers-to-bypass-authorization-plugins-ssgh6g2ei
og:image: https://api.daily.dev/og/posts/sSGH6G2eI.png
og:image:alt: Critical Docker Engine Flaw Allows Attackers to Bypass Authorization Plugins
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Critical Docker Engine Flaw Allows Attackers to Bypass Authorization Plugins

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 3 upvotes · 0 comments

## Summary

Docker has re-patched a critical authorization bypass vulnerability (CVE-2024-41110) affecting specific versions of Docker Engine and Docker Desktop. The flaw, which allows attackers to circumvent AuthZ plugins, was reintroduced in later versions despite an initial fix in 2019. The issue has a maximum CVSS score of 10.0, indicating severe risk. Docker strongly recommends updating to the latest versions—Docker Engine 23.0.14 and 27.1.0, and Docker Desktop 4.33—or implementing temporary mitigation measures if updating is not immediately possible.

## Content

# Docker Addresses Critical Authorization Bypass Vulnerability with New Patches

## Overview
Docker has identified and re-patched a critical vulnerability, CVE-2024-41110, affecting specific versions of Docker Engine and Docker Desktop. This vulnerability, which initially received a fix in Docker Engine v18.09.1 in January 2019, was inadvertently reintroduced in later versions. As of July 2024, Docker has released updated patches and strongly recommends users to apply them.

## Details of the Vulnerability
The critical flaw involves an authorization bypass that allows attackers to circumvent AuthZ plugins under certain conditions, leading to potential privilege escalation. This vulnerability carries a maximum CVSS score of 10.0, underlining the severity of the risk it poses. Docker Engine versions from v19.03 onwards and Docker Desktop up to v4.32.0 are affected by this issue.

## Impact and Recommendations
Docker has provided fixes in the latest versions: Docker Engine versions 23.0.14 and 27.1.0, and Docker Desktop version 4.33. Users are strongly urged to update to these versions to mitigate potential threats, especially if they rely on authorization plugins for access control decisions.

For those unable to update immediately, it is recommended to avoid using AuthZ plugins and to restrict Docker API access to trusted parties to minimize risks.

## Conclusion
Addressing CVE-2024-41110 is crucial for maintaining the security of affected Docker environments. Users should act promptly to apply the patches or follow the temporary mitigation measures to protect their systems from possible exploitation.

## Similar posts on daily.dev

- [Governing Security in the Age of Infinite Signal](https://daily.dev/posts/governing-security-in-the-age-of-infinite-signal-qhihbir44) · Snyk · 0 upvotes · 0 comments
- [No one has a good plan for how AI companies should work with the government](https://daily.dev/posts/no-one-has-a-good-plan-for-how-ai-companies-should-work-with-the-government-nkajqoze1) · TechCrunch · 0 upvotes · 1 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cloud](https://daily.dev/tags/cloud), [#devops](https://daily.dev/tags/devops), [#docker](https://daily.dev/tags/docker), [#vulnerability](https://daily.dev/tags/vulnerability)

[View this post on daily.dev](https://daily.dev/posts/critical-docker-engine-flaw-allows-attackers-to-bypass-authorization-plugins-ssgh6g2ei)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Critical Docker Engine Flaw Allows Attackers to Bypass Authorization Plugins","url":"https://daily.dev/posts/critical-docker-engine-flaw-allows-attackers-to-bypass-authorization-plugins-ssgh6g2ei","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/critical-docker-engine-flaw-allows-attackers-to-bypass-authorization-plugins-ssgh6g2ei"},"datePublished":"2024-07-25T05:53:54.029Z","dateModified":"2024-07-25T12:02:24.183Z","description":"Docker has re-patched a critical authorization bypass vulnerability (CVE-2024-41110) affecting specific versions of Docker Engine and Docker Desktop. The flaw,...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/114dd2b7b38e7e74a09feed47d13d8c8?_a=AQAEuiZ","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/114dd2b7b38e7e74a09feed47d13d8c8?_a=AQAEuiZ","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/critical-docker-engine-flaw-allows-attackers-to-bypass-authorization-plugins-ssgh6g2ei","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":3},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cloud,devops,docker,vulnerability","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Critical Docker Engine Flaw Allows Attackers to Bypass Authorization Plugins"}]}
```

