CVE-2014-6407 is a critical vulnerability affecting Docker versions prior to 1.3.2, allowing remote attackers to write to arbitrary files and execute arbitrary code. This is achieved through symlink or hard link attacks within image archives during pull or load operations. With a CVSS score of 7.5, it has a low attack complexity and no authentication required, enabling potential compromise of confidentiality, integrity, and availability. While there are no known public exploits in Metasploit or ExploitDB, and it's not on the KEV catalog, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.1CPE matchmatch criteria | cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:docker:docker:1.0.0:*:*:*:*:*:*:* | ||
1.3.0CPE matchmatch criteria | cpe:2.3:a:docker:docker:1.3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Arbitrary Code Execution in Docker
Feb 15, 2022CVE-2014-6407
Jul 13, 2021Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.
Dec 2, 2014docker: symbolic and hardlink issues leading to privilege escalation
Nov 24, 2014