VYPR
Moderate severityNVD Advisory· Published Dec 16, 2014· Updated May 6, 2026

CVE-2014-9358

CVE-2014-9358

Description

Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/docker/dockerGo
< 1.3.21.3.2

Affected products

1
  • cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:*
    Range: <=1.3.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.