CVE-2018-15664 is a critical symlink-exchange vulnerability with directory traversal in Docker through version 18.06.1-ce-rc2, specifically impacting the 'docker cp' command. This flaw allows an attacker to gain arbitrary read-write access to the host filesystem with root privileges due to improper archive operations. With a CVSS score of 7.5 (High), exploitation requires local access, high attack complexity, and user interaction, but can lead to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
17.06.0-ceCPE matchmatch criteria | cpe:2.3:a:docker:docker:17.06.0-ce:*:*:*:community:*:*:* | ||
17.06.0-ceCPE matchmatch criteria | cpe:2.3:a:docker:docker:17.06.0-ce:rc1:*:*:community:*:*:* | ||
17.06.0-ceCPE matchmatch criteria | cpe:2.3:a:docker:docker:17.06.0-ce:rc2:*:*:community:*:*:* | ||
17.06.0-ceCPE matchmatch criteria | cpe:2.3:a:docker:docker:17.06.0-ce:rc3:*:*:community:*:*:* | ||
17.06.0-ceCPE matchmatch criteria | cpe:2.3:a:docker:docker:17.06.0-ce:rc4:*:*:community:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.2 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.5 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.