Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2019-12-04T15:05:02
Updated: 2024-08-06T13:10:51.117Z
Reserved: 2014-10-10T00:00:00
Link: CVE-2014-8178
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-12-17T14:15:16.687
Modified: 2023-02-13T00:44:26.523
Link: CVE-2014-8178
Redhat