Noma Security discovered a critical vulnerability called DockerDash in Docker's Ask Gordon AI assistant that allows attackers to compromise environments through malicious metadata labels in Docker images. The flaw exploits a three-stage attack using indirect prompt injection, where the AI assistant reads malicious instructions

3m read timeFrom cloudnativenow.com
Post cover image
Table of contents
Related

Sort: