Описание
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.
Релиз | Статус | Примечание |
---|---|---|
artful | not-affected | 1.13.1-0ubuntu4 |
bionic | not-affected | 1.13.1-0ubuntu4 |
cosmic | not-affected | 1.13.1-0ubuntu4 |
devel | not-affected | 1.13.1-0ubuntu4 |
disco | not-affected | 1.13.1-0ubuntu4 |
esm-apps/bionic | not-affected | 1.13.1-0ubuntu4 |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was deferred] |
esm-infra/xenial | released | 1.10.3-0ubuntu6 |
precise | DNE | |
precise/esm | DNE |
Показывать по
Ссылки на источники
EPSS
1.9 Low
CVSS2
5.5 Medium
CVSS3
Связанные уязвимости
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do no ...
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.
EPSS
1.9 Low
CVSS2
5.5 Medium
CVSS3