Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://www.docker.com/docker-cve-database | vendor advisory |
http://www.securityfocus.com/bid/94228 | vdb entry third party advisory |
http://www.securitytracker.com/id/1037203 | vdb entry |