QID 982541

QID 982541: Go (go) Security Update for github.com/fsouza/go-dockerclient (GHSA-vj3f-3286-r4pf)

Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Critical - 8.5 severity.
  • Solution
    Customers are advised to refer to GHSA-vj3f-3286-r4pf for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982541

    Software Advisories
    Advisory ID Software Component Link
    GHSA-vj3f-3286-r4pf github.com/fsouza/go-dockerclient URL Logo github.com/advisories/GHSA-vj3f-3286-r4pf