Docker before 1.3.1 and docker-py before 0.5.3 fall back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic.
CVSS Details
- CVSS 3.1 Base Score: 5.9
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade docker.io | Jul 30, 2024 | Nov 17, 2014 |
| Docker | — | Upgrade to Docker v1.3.1Upgrade docker-py to version 0.5.3 or higher | May 4, 2017 | Nov 17, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 30, 2014 |
| Suse | — | Upgrade docker-bash-completionUpgrade ruby2.1-rubygem-sle2dockerUpgrade docker-fish-completionUpgrade dockerUpgrade sle2docker | Dec 18, 2015 | Nov 17, 2014 |
| Ubuntu | — | Upgrade docker.io | Nov 19, 2024 | Nov 17, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub