`PUT /containers/{id}/archive` executes container binary on the host
Moby security advisories
All 24 advisories Moby has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.
- Advisories
- 2421 carry a CVE
- critical
- 1
- high
- 5
- medium
- 12
- low
- 6
- Fix in the archive
- 7of 24 matched to a release
- Oldest
- 2 Feb 20215.6 years ago
17 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Newest first
Every productRace condition in docker cp allows creation of arbitrary empty files on the host via symlink swap
Race condition in docker cp allows bind mount redirection to host path
AuthZ plugin bypass with oversized request body
Off-by-one error in plugin privilege validation
Firewalld reload removes bridge network isolation
Firewalld reload makes published container ports accessible from remote hosts
Authz zero length regression
IPv6 enabled on IPv4-only network interfaces
External DNS requests from 'internal' networks could lead to data exfiltration
Classic builder cache poisoning
/sys/devices/virtual/powercap accessible by default to containers
Encrypted overlay network may be unauthenticated
Encrypted overlay network traffic may be unencrypted
Encrypted overlay network with a single endpoint is unauthenticated
The Swarm VXLAN port may be exposed to attack due to ambiguous documentation
Container build can leak any path on the host into the container (using Git CVE-2022-39253)
Security vulnerability relating to supplementary group permissions
Default inheritable capabilities for linux container should be empty
Ambiguous OCI manifest parsing
`docker cp` allows unexpected chmod of host files
Insufficiently restricted permissions on data directory
Docker daemon crash during image pull of malicious image
Access to remapped root allows privilege escalation to real root