FlawAtlas
Search the atlas
CVE-2014-9358 Moderate

CVE-2014-9358

Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."

Exploit probability 2.5%
Published December 16, 2014
Required by Not available
Last source change April 10, 2026

02 / AFFECTED SOFTWARE

Affected packages

Go github.com/docker/docker
Go github.com/docker/docker

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2014-9358

Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."

View original source
Open Source Vulnerabilities GHSA-qmmc-jppf-32wv

Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."

View original source

05 / REFERENCES

Further evidence