BETA
This is a BETA experience. You may opt-out by clicking here

More From Forbes

Edit Story

Docker Discovers Major Vulnerability--Latest Version Immune

This article is more than 9 years old.

News from Docker, the vendor behind the eponymous Docker containerization initiative, that a discovery has been made of a critical flaw in some versions of the software. From the notification:

The Docker engine, up to and including version 1.3.1, was vulnerable to extracting files to arbitrary paths on the host during ‘docker pull’ and‘docker load’ operations.

The vulnerability, discovered by Florian Weimer of Red Hat Product Security and independent researcher, Tõnis Tiigi allowed for a remote code escalation to occur. Docker has remedied the flaw and the latest version of the product, 1.3.2 is no longer vulnerable.

Docker had a previous security issue back in June and that vulnerability was also quickly patched.

There is, however, no remediation available for older versions of Docker with this previous bug, a cautionary tale for organizations experimenting with early stage projects. While it is in no way an indictment of the Docker project, it does show that early-stage projects are just that – early and still a little rough around the edged.

This is a particularly important issue given the massive momentum that Docker has – while it means more attention from security professionals and hence the early identification of issues, the widespread use of Docker also increases the potential threat from vulnerabilities.

Follow me on TwitterCheck out my website