Vulnerability Details CVE-2020-14298
The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malicious or compromised container to compromise the container host and other containers running on the same host. This issue only affects docker version 1.13.1-108.git4ef4b30.el7, shipped in Red Hat Enterprise Linux 7 Extras. Both earlier and later versions are not affected.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 35.6%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 4.6
Products affected by CVE-2020-14298
-
cpe:2.3:a:docker:docker:1.13.1
-
cpe:2.3:a:redhat:openshift_container_platform:3.0
-
cpe:2.3:a:redhat:openshift_container_platform:3.1
-
cpe:2.3:a:redhat:openshift_container_platform:3.2
-
cpe:2.3:a:redhat:openshift_container_platform:3.3
-
cpe:2.3:a:redhat:openshift_container_platform:3.4
-
cpe:2.3:a:redhat:openshift_container_platform:3.5
-
cpe:2.3:a:redhat:openshift_container_platform:3.6
-
cpe:2.3:a:redhat:openshift_container_platform:3.7
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.14
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.23
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.42-2
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.44
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.46
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.52
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.53
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.54
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.57
-
cpe:2.3:a:redhat:openshift_container_platform:3.7.61
-
cpe:2.3:o:redhat:enterprise_linux_server:7.0