Certain versions of Docker Engine have a security vulnerability that could allow an attacker to bypass authorization plugins (AuthZ) under specific circumstances. The base likelihood of this being exploited is low.
CVE-2024-41110 will not affect ASUSTOR products with ADM 4.1 onward which the Docker Engine is installed, unless the users install AuthZ plugin and use it by themselves. Updates with new Docker Engine version will be released as soon as possible.
- Docker Engine v27.1.1.r1 has been updated on the App Central for ADM 4.1 and above to resolve the issues.