CVE-2020-14300

The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was missing multiple bug and security fixes. One of the fixes regressed in that update was the fix for CVE-2016-9962, that was previously corrected in the docker packages in Red Hat Enterprise Linux 7 Extras via RHSA-2017:0116 (https://access.redhat.com/errata/RHSA-2017:0116). The CVE-2020-14300 was assigned to this security regression and it is specific to the docker packages produced by Red Hat. The original issue - CVE-2016-9962 - could possibly allow a process inside container to compromise a process entering container namespace and execute arbitrary code outside of the container. This could lead to compromise of the container host or other containers running on the same container host. This issue only affects a single version of Docker, 1.13.1-108.git4ef4b30, shipped in Red Hat Enterprise Linux 7. Both earlier and later versions are not affected.

Published: 2020-07-13 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2020-14300 is rated Moderate Risk (55.7/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.36%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2020-14300

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-05-13 0.27% 0.36% +0.09%
2 2026-04-01 0.08% 0.27% +0.18%
3 2026-02-16 0.08%

Full EPSS history (21 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2020-14300

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
8.8 3.1 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
2.0 6.0 [email protected]
4.6 2.0 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
3.9 6.4 [email protected]

Weakness enumeration for CVE-2020-14300

OS Trackers for CVE-2020-14300

vendor priority summary link
debian unimportant CVE-2020-14300 unimportant priority: Debian including 1 source packages (docker.io), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2020-14300
redhat high https://access.redhat.com/security/cve/CVE-2020-14300
suse high CVE-2020-14300 severity important: SUSE including 3 source package names (docker, docker-bash-completion, docker-kubic), 13 product×package rows across 9 product lines (Magnum Orchestration 7, SUSE CaaS Platform 3.0, … (9 product lines)): Known Not Affected 13. https://www.suse.com/security/cve/CVE-2020-14300/
ubuntu low CVE-2020-14300 low priority: Ubuntu including 1 source packages (docker.io), 6 status rows across 6 suites (bionic, eoan, focal, trusty, upstream, xenial): not-affected 5, DNE 1. https://ubuntu.com/security/CVE-2020-14300

Affected software / configurations for CVE-2020-14300

Vendor Product Version Raw CPE
docker docker 1.13.1 cpe:2.3:a:docker:docker:1.13.1:*:*:*:*:*:*:*
redhat enterprise_linux_server 7.0 cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*

References for CVE-2020-14300

cvelogic Threat Intelligence