Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade docker.io | Jul 30, 2024 | Dec 12, 2014 |
| Docker | — | Upgrade to Docker v1.3.2 | May 4, 2017 | Dec 12, 2014 |
| Oracle_linux | — | Upgrade dockerUpgrade docker-pkg-develUpgrade docker-devel | Oct 16, 2024 | Dec 12, 2014 |
| Suse | — | Upgrade dockerUpgrade docker-bash-completionUpgrade ruby2.1-rubygem-sle2dockerUpgrade sle2dockerUpgrade docker-fish-completion | Dec 18, 2015 | Dec 12, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub