CVE-2014-9358: Input Validation
Published Dec 16, 2014
·Updated
Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."
Affected Software
1 affected component
Docker docker<=1.3.2
Event History
Dec 16, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9358?
CVE-2014-9358 is classified as a medium severity vulnerability due to potential path traversal attacks.
2
How do I fix CVE-2014-9358?
To fix CVE-2014-9358, upgrade Docker to version 1.3.3 or later.
3
What software is affected by CVE-2014-9358?
CVE-2014-9358 affects Docker versions prior to 1.3.3.
4
What type of attacks can be executed through CVE-2014-9358?
CVE-2014-9358 allows remote attackers to conduct path traversal attacks and spoof repositories.
5
In which operations is CVE-2014-9358 exploitable?
CVE-2014-9358 is exploitable during "docker load" operations and through registry communications.