CVE-2014-5282Improper Input Validation in Docker

Severity
8.1HIGHNVD
EPSS
0.6%
top 31.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 6
Latest updateMay 14

Description

Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image through the loading of untrusted images via 'docker load'.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages5 packages

🔴Vulnerability Details

2
GHSA
GHSA-68xv-f463-9gx3: Docker before 12022-05-14
OSV
CVE-2014-5282: Docker before 12018-02-06

📋Vendor Advisories

3
Microsoft
Docker before 1.3 does not properly validate image IDs which allows remote attackers to redirect to another image through the loading of untrusted images via 'docker load'.2018-02-13
Red Hat
docker: tagging image to ID can redirect images on subsequent pulls2014-10-16
Debian
CVE-2014-5282: docker.io - Docker before 1.3 does not properly validate image IDs, which allows remote atta...2014

💬Community

1
Bugzilla
CVE-2014-5282 docker: tagging image to ID can redirect images on subsequent pulls2014-11-26