CVE-2014-9356 describes a path traversal vulnerability in Docker versions prior to 1.3.3. This flaw allows remote attackers to write to arbitrary files and bypass container protection mechanisms by exploiting symlinks within Docker images or builds. With a CVSS score of 8.6 (High), this vulnerability is critical due to its network-based attack vector, low complexity, and high impact on integrity, enabling unauthorized file modification. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not listed in CISA's KEV catalog, the vulnerability has garnered significant community discussion and media coverage, indicating awareness despite a low EPSS score.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.3CPE matchmatch criteria | cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2014-9356
Jul 13, 2021Path Traversal in Docker
May 18, 2021Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.
Dec 10, 2019docker: Path traversal during processing of absolute symlinks
Dec 11, 2014