FlawAtlas
Search the atlas
CVE-2015-3630 High

Information Exposure in Docker Engine in github.com/docker/docker

Information Exposure in Docker Engine in github.com/docker/docker

Exploit probability 0.5%
Published August 21, 2024
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Go github.com/docker/docker
Go github.com/docker/docker

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2015-3630

Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image.

View original source
Open Source Vulnerabilities GO-2022-0638

Information Exposure in Docker Engine in github.com/docker/docker

View original source
Open Source Vulnerabilities GHSA-8fvr-5rqf-3wwh

Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image.

View original source

05 / REFERENCES

Further evidence