Vulnerability Description
Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Docker | Docker | <= 1.3.2 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/archive/1/534215/100/0/threaded
- https://groups.google.com/forum/#%21msg/docker-user/nFAz-B-n4Bw/0wr3wvLsnUwJ
- http://www.securityfocus.com/archive/1/534215/100/0/threaded
- https://groups.google.com/forum/#%21msg/docker-user/nFAz-B-n4Bw/0wr3wvLsnUwJ
FAQ
What is CVE-2014-9358?
CVE-2014-9358 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or...
How severe is CVE-2014-9358?
CVE-2014-9358 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-9358?
Check the references section above for vendor advisories and patch information. Affected products include: Docker Docker.