Lucene search

K
cve[email protected]CVE-2014-9358
HistoryDec 16, 2014 - 6:59 p.m.

CVE-2014-9358

2014-12-1618:59:16
CWE-20
web.nvd.nist.gov
39
cve-2014-9358
docker security
path traversal attack
repository spoofing
image validation
remote code execution

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

8.1 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.1%

Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) “docker load” operation or (2) “registry communications.”

Affected configurations

NVD
Node
dockerdockerRange1.3.2
CPENameOperatorVersion
docker:dockerdockerle1.3.2

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

8.1 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.1%