VulnerabilityModified
CVE-2014-5282
Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image through the loading of untrusted images via 'docker load'.
HIGH 8.1EPSS 1.32%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image through the loading of untrusted images via 'docker load'.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 1.32% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- docker/docker
- Source
- cve@mitre.org
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1168436Issue Tracking, Third Party Advisory
- https://groups.google.com/forum/#%21msg/docker-announce/aQoVmQlcE0A/smPuBNYf8VwJ
- https://bugzilla.redhat.com/show_bug.cgi?id=1168436Issue Tracking, Third Party Advisory
- https://groups.google.com/forum/#%21msg/docker-announce/aQoVmQlcE0A/smPuBNYf8VwJ
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.