PT-2014-7211 · Docker+1 · Docker+1
Published
2014-12-08
·
Updated
2025-10-11
·
CVE-2014-6408
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Docker versions 1.3.0 through 1.3.1
Description
The issue allows remote attackers to modify the default run profile of image containers. This could possibly lead to bypassing the container by applying unspecified security options to an image.
Recommendations
For Docker versions 1.3.0 through 1.3.1, consider restricting access to the default run profile of image containers until a fix is available. As a temporary workaround, review and limit the application of security options to images to minimize the risk of exploitation.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Docker
Suse