CVE Vulnerabilities

CVE-2016-8867

Published: Oct 28, 2016 | Modified: Jul 28, 2017
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Ubuntu

Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.

Affected Software

Name Vendor Start Version End Version
Docker Docker 1.12.2 (including) 1.12.2 (including)
Red Hat Enterprise Linux 7 Extras RedHat docker-2:1.13.1-162.git64e9980.el7_8 *

References