PT-2016-7599 · Docker+1 · Docker Engine+2
Publicado
2016-10-28
·
Atualizado
2025-10-11
·
CVE-2016-8867
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Docker Engine version 1.12.2
Description
The issue allows malicious images to bypass user permissions and access files within the container filesystem or mounted volumes due to misconfigured capability policies.
Recommendations
For Docker Engine version 1.12.2, consider disabling ambient capabilities until a proper configuration or patch is available to prevent malicious images from bypassing user permissions.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Docker
Docker Engine
Suse