← Back

CVE-2014-5277

nvd nist
Published: Nov 17, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Docker before 1.3.1 and docker-py before 0.5.3 fall back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic.

Affected (2)

Products: Docker: Docker, Docker Py
2 products
Docker
Docker Py
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.3.0
Up to 0.5.3

Related CWEs

Timeline

No history available yet.