Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade docker-novolume-pluginUpgrade docker-lvm-pluginUpgrade docker-v1.10-migratorUpgrade docker-debuginfoUpgrade dockerUpgrade docker-rhel-push-pluginUpgrade docker-commonUpgrade docker-clientUpgrade docker-logrotate | Jun 24, 2020 | Oct 28, 2016 |
| Docker | — | Upgrade to Docker v1.12.3 | May 4, 2017 | Oct 28, 2016 |
| Oracle_linux | — | Upgrade docker-engineUpgrade docker-engine-selinux | Jan 14, 2017 | Oct 28, 2016 |
| Redhat_linux | — | Upgrade docker-novolume-pluginUpgrade dockerUpgrade docker-lvm-pluginUpgrade docker-v1.10-migratorUpgrade docker-debuginfoUpgrade docker-logrotateUpgrade docker-rhel-push-pluginUpgrade docker-clientUpgrade docker-common | Jun 24, 2020 | Oct 28, 2016 |
| Suse | — | Upgrade ruby2.1-rubygem-docker-apiUpgrade ruby2.1-rubygem-exconUpgrade containerdUpgrade docker-bash-completionUpgrade dockerUpgrade runcUpgrade docker-fish-completion | Dec 5, 2016 | Oct 28, 2016 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 28, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub