Insecure session management In docker.io
Description
Directory Traversal in Docker Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 14 | 1.3.3~dfsg1-1 | ||
go | 1.3.2 | ||
debian 13 | 1.3.3~dfsg1-1 | ||
debian 12 | 1.3.3~dfsg1-1 | ||
debian 11 | 1.3.3~dfsg1-1 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4.