Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Mageia 7: 2020-0406 Security Advisory on Docker Remote Access Risk

mageia
Calendar Grey November 9, 2020
Dist Mageia Esm H88
Recent updates to Docker packages remedy a security flaw that potentially reveals confidential data, affecting users of Mageia 7.
It was discovered that Docker could be made to expose sensitive information when processing URLs in container image manifests

Summary

It was discovered that Docker could be made to expose sensitive information when processing URLs in container image manifests. A remote attacker could use this to trick the user and obtain the user's registry credentials (CVE-2020-15157).

References

- https://bugs.mageia.org/show_bug.cgi?id=27437

- https://www.openwall.com/lists/oss-security/2020/10/15/1

- https://ubuntu.com/security/notices/USN-4589-2

- https://www.cve.org/CVERecord?id=CVE-2020-15157

Resolution

SRPMS

- 7/core/docker-18.09.9-1.2.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 09 Nov 2020
URL: https://advisories.mageia.org/MGASA-2020-0406.html
Type: security
CVE: CVE-2020-15157

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here