7.5
CVSSv3

CVE-2016-8867

Published: 28/10/2016 Updated: 28/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

docker docker 1.12.2

Vendor Advisories

Synopsis Important: docker security update Type/Severity Security Advisory: Important Topic An update for docker is now available for Red Hat Enterprise Linux 7 ExtrasRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base s ...
Docker Engine 1122 enabled ambient capabilities with misconfigured capability policies This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes ...