First published: Wed Dec 04 2019(Updated: )
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Docker Cs Engine | <1.6.2-cs7 | |
Docker Docker | <1.8.3 | |
openSUSE openSUSE | =13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2014-8178.
The severity of CVE-2014-8178 is medium.
The affected software for CVE-2014-8178 is Docker Engine before version 1.8.3 and CS Docker Engine before version 1.6.2-CS7.
CVE-2014-8178 makes it easier for attackers to poison the image cache in Docker by using a crafted image in pull or push commands.
To fix CVE-2014-8178, update Docker Engine to version 1.8.3 or CS Docker Engine to version 1.6.2-CS7.