The Docker daemon managed by boot2docker 1.2 and earlier improperly enables unauthenticated TCP connections by default, which makes it easier for remote attackers to gain privileges or execute arbitrary code from children containers.
References
Link | Resource |
---|---|
https://groups.google.com/forum/#!msg/docker-announce/aQoVmQlcE0A/smPuBNYf8VwJ | Third Party Advisory |
Configurations
Information
Published : 2018-02-06 08:29
Updated : 2019-04-29 10:14
NVD link : CVE-2014-5279
Mitre link : CVE-2014-5279
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
boot2docker
- boot2docker