Skip to content

Path Traversal in Docker

High severity GitHub Reviewed Published May 18, 2021 to the GitHub Advisory Database • Updated Jan 9, 2023

Package

gomod github.com/docker/docker (Go)

Affected versions

< 1.3.3

Patched versions

1.3.3
gomod github.com/moby/moby (Go)
< 1.3.3
1.3.3

Description

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

References

Reviewed May 17, 2021
Published to the GitHub Advisory Database May 18, 2021
Last updated Jan 9, 2023

Severity

High

Weaknesses

CVE ID

CVE-2014-9356

GHSA ID

GHSA-vj3f-3286-r4pf

Source code

No known source code

Credits

Checking history
See something to contribute? Suggest improvements for this vulnerability.