Описание
Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.
Ссылки
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:docker:docker:1.12.2:*:*:*:*:*:*:*
EPSS
Процентиль: 84%
0.02731
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-264
Связанные уязвимости
CVSS3: 7.5
redhat
почти 10 лет назад
Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.
CVSS3: 7.5
debian
почти 10 лет назад
Docker Engine 1.12.2 enabled ambient capabilities with misconfigured c ...
EPSS
Процентиль: 84%
0.02731
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-264