« Volver al listado

CVE-2014-5277

Estado: ModificadaMedia (5)—

Docker before 1.3.1 and docker-py before 0.5.3 fall back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-5277",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-11-17T16:59:01.480",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-11/msg00048.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://groups.google.com/forum/#%21topic/docker-user/oYm0i3xShJU",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-11/msg00048.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://groups.google.com/forum/#%21topic/docker-user/oYm0i3xShJU",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-17"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Docker before 1.3.1 and docker-py before 0.5.3 fall back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic."
    },
    {
      "lang": "es",
      "value": "Docker anterior a 1.3.1 y docker-py anterior a 0.5.3 recurre a HTTP cuando la conexión HTTPS del registro falla, lo que permite a atacantes realizar ataques de man-in-the-middle y ataques de downgrade con el fin de obtener datos de autenticación y de imagen, aprovechándose de su posición en la red, es decir, entre el cliente y el registro para bloquear el tráfico HTTPS."
    }
  ],
  "lastModified": "2026-06-17T00:11:19.450",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D0B3A3E-0268-4434-BCC8-0A4CFB2A3026",
              "versionEndIncluding": "1.3.0"
            },
            {
              "criteria": "cpe:2.3:a:docker:docker-py:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "751950F1-1BA3-4504-A258-EFA6CE8975E2",
              "versionEndIncluding": "0.5.3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}