« Volver al listado

Docker

Docker Engine: vulnerabilidades y CVE

Docker Engine tiene 8 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses5
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-42306Alta (7.2)0.10%—12 jun 2026
Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount…
CVE-2026-41568Media (6.1)0.10%—12 jun 2026
Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount…
CVE-2026-41567Alta (7.2)0.17%—5 jun 2026
Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped…
CVE-2026-34040Alta (7.8)0.16%—31 mar 2026
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version…
CVE-2026-33997Alta (8.1)0.51%—31 mar 2026
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in…
CVE-2024-41110Crítica (9.9)16%—24 jul 2024
Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions of Docker Engine, which could allow an attacker to bypass authorization…
CVE-2020-13401Media (6)2.8%—2 jun 2020
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive…
CVE-2018-20699Media (4.9)2.2%—12 ene 2019
Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go,…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution3
  2. T1068 Exploitation for Privilege Escalation1
  3. T1078 Valid Accounts1
  4. T1098 Account Manipulation1
  5. T1565.001 Stored Data Manipulation1
  6. T1574.007 Path Interception by PATH Environment Variable1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Docker