Information Exposure in Docker Engine
High severity
GitHub Reviewed
Published
Feb 15, 2022
to the GitHub Advisory Database
•
Updated Jul 8, 2024
Description
Reviewed
May 19, 2021
Published to the GitHub Advisory Database
Feb 15, 2022
Last updated
Jul 8, 2024
Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image.
References