CVE-2014-8179 - Opensuse Opensuse, Docker Docker and Docker Cs Engine

Critical 7.5

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.

Affected software

Opensuse Opensuse

Docker Docker

Docker Cs Engine

Reference links

Get alerted to vulnerabilities in your software

CVE alerts, vulnerability alerts, latest versions and news matched to your software stack.