PT-2020-7588 · Docker · Docker

Published

2020-01-02

·

Updated

2023-03-01

·

CVE-2014-0048

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Docker versions prior to 1.6.0
Description An issue was found where some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways. This poses a risk due to the lack of encryption and authentication in HTTP, making it possible for attackers to intercept and modify the data being downloaded.
Recommendations For Docker versions prior to 1.6.0, update to version 1.6.0 or later to resolve the issue. As a temporary workaround, consider restricting the execution of scripts and programs downloaded via HTTP until a patch is available. Avoid using HTTP for downloading and executing programs and scripts in Docker until the issue is resolved.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2014-0048

Affected Products

Docker