This page aggregates publicly disclosed CVE and security risk information related to boot2docker, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2014-5280 | boot2docker 1.2 and earlier allows attackers to conduct cross-site request forgery (CSRF) attacks by leveraging Docker daemons enabling TCP connections without TLS authentication. | [email protected] | 8.8 | 0.07% | 2018-02-06 | 2024-11-21 |
| CVE-2014-5279 | The Docker daemon managed by boot2docker 1.2 and earlier improperly enables unauthenticated TCP connections by default, which makes it easier for remote attackers to gain privileges or execute arbitrary code from children containers. | [email protected] | 8.8 | 2.45% | 2018-02-06 | 2024-11-21 |