CVE-2014-6408: Medium severity Docker docker vulnerability
Published Dec 12, 2014
·Updated
Docker 1.3.0 through 1.3.1 allows remote attackers to modify the default run profile of image containers and possibly bypass the container by applying unspecified security options to an image.
Affected Software
2 affected components
Docker docker=1.3.0
Docker docker=1.3.1
Event History
Dec 12, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6408?
CVE-2014-6408 has a medium severity level as it allows remote attackers to modify container profiles.
2
How do I fix CVE-2014-6408?
To address CVE-2014-6408, upgrade Docker to version 1.3.2 or later where the vulnerability is patched.
3
What versions of Docker are affected by CVE-2014-6408?
CVE-2014-6408 affects Docker versions 1.3.0 and 1.3.1.
4
What type of attack does CVE-2014-6408 enable?
CVE-2014-6408 enables remote attackers to modify the default run profile of image containers.
5
Are there any known exploits for CVE-2014-6408?
While specific exploits for CVE-2014-6408 are not detailed, the vulnerability poses a risk for unauthorized access and manipulation of containers.