CVE-2018-15664 - CVE House
Back to Database
Status published High CVE-2018-15664

In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker...

Vulnerability Description

In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access to the host filesystem with root privileges, because daemon/archive.go does not do archive operations on a frozen filesystem (or from within a chroot).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-15664

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

docker
Vulnerable Versions:
17.06.0-ce, 17.06.1-ce, 17.06.2-ce, 17.07.0-ce, 17.09.0-ce, 17.09.1-ce, 17.09.1-ce-, 17.10.0-ce, 17.11.0-ce, 17.12.0-ce, 17.12.1-ce, 18.01.0-ce, 18.02.0-ce, 18.03.0-ce, 18.03.1-ce, 18.04.0-ce, 18.05.0-ce, 18.06.0-ce, 18.06.1-ce

Timeline

Official Publish: May 23rd, 2019
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.