CVE-2014-8178: Input Validation
Published Dec 4, 2019
·Updated
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.
Affected Software
3 affected components
Docker Cs Engine<1.6.2-cs7
Docker Docker<1.8.3
openSUSE openSUSE=13.2
Remediation
Event History
Dec 4, 2019
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2014-8178.
2
What is the severity of CVE-2014-8178?
The severity of CVE-2014-8178 is medium.
3
What is the affected software for CVE-2014-8178?
The affected software for CVE-2014-8178 is Docker Engine before version 1.8.3 and CS Docker Engine before version 1.6.2-CS7.
4
How does CVE-2014-8178 affect the image cache in Docker?
CVE-2014-8178 makes it easier for attackers to poison the image cache in Docker by using a crafted image in pull or push commands.
5
How can I fix CVE-2014-8178?
To fix CVE-2014-8178, update Docker Engine to version 1.8.3 or CS Docker Engine to version 1.6.2-CS7.