CVE-2016-8867Docker vulnerability

CWE-2644 documents4 sources
Severity
7.5HIGHNVD
EPSS
0.4%
top 39.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 28
Latest updateOct 31

Description

Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDdocker/docker1.12.2
debiandebian/runc

📋Vendor Advisories

2
Red Hat
docker: Ambient capability usage in containers2016-10-24
Debian
CVE-2016-8867: docker.io - Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability ...2016

💬Community

1
Bugzilla
CVE-2016-8867 docker: Ambient capability usage in containers2016-10-31