CVE-2014-9356

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
02/12/2019
Last modified:
11/12/2019

Description

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:* 1.3.3 (excluding)