PT-2014-6389 · Docker+1 · Docker-Py+2

Published

2014-11-17

·

Updated

2025-10-11

·

CVE-2014-5277

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Docker versions prior to 1.3.1 docker-py versions prior to 0.5.3
Description The issue allows man-in-the-middle attackers to conduct downgrade attacks. This can be achieved by leveraging a network position between the client and the registry to block HTTPS traffic, causing the client to fall back to HTTP. As a result, attackers can obtain authentication and image data.
Recommendations For Docker versions prior to 1.3.1, update to version 1.3.1 or later to resolve the issue. For docker-py versions prior to 0.5.3, update to version 0.5.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the Docker registry to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2014-5277
GHSA-8W94-CF6G-C8MG
GO-2022-0636
OPENSUSE-SU-2024:10532-1
OPENSUSE-SU-2025:15589-1
PYSEC-2014-80
SUSE-SU-2014_1648-1
SUSE-SU-2025:03540-1
SUSE-SU-2025:03545-1

Affected Products

Docker
Suse
Docker-Py