Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-8020 | Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation. |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T13:10:51.252Z
Reserved: 2014-10-10T00:00:00.000Z
Link: CVE-2014-8179
No data.
Status : Modified
Published: 2019-12-17T18:15:13.497
Modified: 2026-06-17T00:16:26.700
Link: CVE-2014-8179
OpenCVE Enrichment
No data.
-
CWE-20
Improper Input Validation
EUVD