Back to search

CVE-2014-9358

MEDIUM
6.4NVD

Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."

CVSS v2.0 Score

6.4
/ 10.0
MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N

Information

Published
16 déc. 2014
Updated
12 avr. 2025
Status
Deferred
Source
cve@mitre.org

Affected products

docker dockerAll Docker CVEs →
Versions : 1.3.2

Weaknesses (CWE)

CWE-20

Similar CVEs

Other vulnerabilities of type CWE-20

Loading…

Monitor your products

Get automatic alerts for every new CVE affecting your equipment.

Enable monitoring