Vulnerabilities
Vulnerable Software
Docker:  >> Docker  >> 1.12.2  Security Vulnerabilities
RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to container escapes or modification of runC state before the process is fully placed inside the container.
CVSS Score
6.4
EPSS Score
0.002
Published
2017-01-31
Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.
CVSS Score
7.5
EPSS Score
0.004
Published
2016-10-28


Contact Us

Shodan ® - All rights reserved