PT-2019-7142 · Docker+1 · Docker Engine+2

Published

2015-10-14

·

Updated

2025-10-11

·

CVE-2014-8179

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Docker Engine versions prior to 1.8.3 CS Docker Engine versions prior to 1.6.2-CS7
Description The issue arises from improper validation and extraction of the manifest object from its JSON representation during a pull. This allows attackers to inject new attributes in a JSON object, effectively bypassing pull-by-digest validation.
Recommendations For Docker Engine versions prior to 1.8.3, update to version 1.8.3 or later to resolve the issue. For CS Docker Engine versions prior to 1.6.2-CS7, update to version 1.6.2-CS7 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8179
MGASA-2016-0043
OPENSUSE-SU-2024:10532-1
OPENSUSE-SU-2025:15589-1
SUSE-SU-2015:1757-1
SUSE-SU-2025:03540-1
SUSE-SU-2025:03545-1

Affected Products

Docker
Docker Engine
Suse