Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
220 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.49% | — | Docker CS EngineDockerOpensuse | 17/12/2019 | 17/6/2026 | Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull or push commands. | |
| Modificada | Alta (8.6) | 4.9% | — | Docker | 2/12/2019 | 17/6/2026 | Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile. | |
| Modificada | Alta (7.5) | 4.4% | — | Linuxfoundation RuncDockerFedoraproject FedoraOpensuse Leap+6 | 25/9/2019 | 17/6/2026 | runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory. | |
| Analizada | Alta (7.8) | 49% | ⚠ Explotación activa💥 Exploit | DockerApache Geode | 28/8/2019 | 17/6/2026 | Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker, restart Docker, or run… | |
| Modificada | Alta (8.4) | 2.0% | — | Docker | 22/8/2019 | 17/6/2026 | In Docker before 18.09.4, an attacker who is capable of supplying or manipulating the build path for the "docker build" command would be able to gain command execution. An issue exists in the way "docker build" processes remote git URLs, and results in command injection into the underlying "git clone" command, leading… | |
| Modificada | Crítica (9.8) | 19% | 💥 PoC | DockerDebian LinuxOpensuse Leap | 29/7/2019 | 17/6/2026 | In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container. | |
| Modificada | Media (5.5) | 0.41% | — | Docker Credential HelpersFedoraproject FedoraCanonical Ubuntu Linux | 29/7/2019 | 17/6/2026 | docker-credential-helpers before 0.6.3 has a double free in the List functions. | |
| Modificada | Alta (7.5) | 3.7% | — | Docker | 18/7/2019 | 17/6/2026 | In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docker stack deploy is run to redeploy a stack that includes (non external) secrets. It potentially… | |
| Modificada | Media (4.3) | 1.4% | — | Jenkins Docker | 11/7/2019 | 17/6/2026 | A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins. | |
| Modificada | Media (6.5) | 1.7% | — | Jenkins Docker | 11/7/2019 | 17/6/2026 | A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Alta (8.8) | 1.4% | — | Jenkins Docker | 11/7/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in… | |
| Modificada | Alta (7.5) | 3.4% | — | Docker | 23/5/2019 | 17/6/2026 | In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access to the host filesystem with root privileges, because daemon/archive.go does not do archive operations on a frozen… | |
| Modificada | Crítica (9.8) | 6.3% | — | Gliderlabs Docker-alpineOpensuse LeapF5 Big-ip Controller | 8/5/2019 | 17/6/2026 | Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize… | |
| Modificada | Alta (8.8) | 1.4% | — | Jenkins Cloudshare Docker-machine | 4/4/2019 | 17/6/2026 | Jenkins CloudShare Docker-Machine Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Alta (8.6) | 98% | 💥 Exploit | DockerLinuxfoundation RuncRedhat Container Development KITRedhat Openshift+15 | 11/2/2019 | 17/6/2026 | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image,… | |
| Modificada | Media (4.9) | 2.2% | — | Docker EngineRedhat Enterprise Linux Server | 12/1/2019 | 17/6/2026 | Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go. | |
| Modificada | Alta (8.8) | 2.5% | — | Docker | 1/9/2018 | 17/6/2026 | HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\pipe\dockerBackend named pipe without verifying the validity of the deserialized .NET objects. This would allow a malicious user in the "docker-users" group (who may not… | |
| Modificada | Media (5.3) | 1.1% | — | DockerMobyproject MobyRedhat OpenstackRedhat Enterprise Linux+2 | 6/7/2018 | 17/6/2026 | The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness. | |
| Modificada | Crítica (9.8) | 1.3% | — | Docker Notary | 31/3/2018 | 17/6/2026 | In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment stating that it does. Even if a user creates a new root.json file after a key compromise, an attacker can produce update files referring to an old root.json file. | |
| Modificada | Alta (7.5) | 1.0% | — | Docker Notary | 31/3/2018 | 17/6/2026 | In Docker Notary before 0.1, gotuf/signed/verify.go has a Signature Algorithm Not Matched to Key vulnerability. Because an attacker controls the field specifying the signature algorithm, they might (for example) be able to forge a signature by forcing a misinterpretation of an RSA-PSS key as Ed25519 elliptic-curve… | |
| Modificada | Alta (8.1) | 1.3% | — | Docker | 6/2/2018 | 17/6/2026 | Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image through the loading of untrusted images via 'docker load'. | |
| Modificada | Alta (8.8) | 0.73% | — | Boot2docker | 6/2/2018 | 17/6/2026 | boot2docker 1.2 and earlier allows attackers to conduct cross-site request forgery (CSRF) attacks by leveraging Docker daemons enabling TCP connections without TLS authentication. | |
| Modificada | Alta (8.8) | 2.8% | — | Boot2docker | 6/2/2018 | 17/6/2026 | The Docker daemon managed by boot2docker 1.2 and earlier improperly enables unauthenticated TCP connections by default, which makes it easier for remote attackers to gain privileges or execute arbitrary code from children containers. | |
| Modificada | Media (6.5) | 2.5% | — | Docker | 1/11/2017 | 17/6/2026 | Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a crafted image layer payload, aka gzip bombing. | |
| Modificada | Alta (7.8) | 0.39% | — | Docker | 6/10/2017 | 17/6/2026 | Docker before 1.5 allows local users to have unspecified impact via vectors involving unsafe /tmp usage. |