CVE-2016-8867

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
28/10/2016
Last modified:
12/04/2025

Description

Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:docker:docker:1.12.2:*:*:*:*:*:*:*