PT-2014-7211 · Docker+1 · Docker+1

CVE-2014-6408

·

Publicado

2014-12-08

·

Atualizado

2025-10-11

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Docker versions 1.3.0 through 1.3.1
Description The issue allows remote attackers to modify the default run profile of image containers. This could possibly lead to bypassing the container by applying unspecified security options to an image.
Recommendations For Docker versions 1.3.0 through 1.3.1, consider restricting access to the default run profile of image containers until a fix is available. As a temporary workaround, review and limit the application of security options to images to minimize the risk of exploitation.

Correção

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-6408
GHSA-44GG-PMQR-4669
GO-2022-0625
OPENSUSE-SU-2014_1596-1
OPENSUSE-SU-2024:10532-1
OPENSUSE-SU-2025:15589-1
SUSE-SU-2025:03540-1
SUSE-SU-2025:03545-1

Produtos afetados

Docker
Suse