Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image through the loading of untrusted images via 'docker load'.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade docker.io | Jul 30, 2024 | Feb 6, 2018 |
| Docker | — | Upgrade to Docker v1.3 | Apr 27, 2018 | Feb 6, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 6, 2018 |
| Suse | — | Upgrade ruby2.1-rubygem-sle2dockerUpgrade dockerUpgrade sle2docker | Dec 18, 2015 | Dec 15, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub