CVE-2014-8179 describes a vulnerability in Docker Engine versions prior to 1.8.3 and CS Docker Engine prior to 1.6.2-CS7. This flaw allows attackers to bypass pull-by-digest validation by injecting new attributes into a JSON object during manifest extraction. With a CVSS score of 7.5 (HIGH), this vulnerability has a low attack complexity and can lead to high integrity impact, allowing unauthorized modifications. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.2-cs7CPE matchmatch criteria | cpe:2.3:a:docker:cs_engine:*:*:*:*:*:*:*:* | ||
< 1.8.3CPE matchmatch criteria | cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:* | ||
13.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2014-8179
Jul 13, 2021Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.
Dec 10, 2019docker: Manifest validation and parsing logic errors allow pull-by-digest validation bypass
Oct 13, 2015