Back

MEDIUM

docker: fallback to HTTP when HTTPS connections to the registry fail

Published Nov 17, 2014

Description

Docker before 1.3.1 and docker-py before 0.5.3 fall back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 17, 2014
Updated Aug 6, 2024
Reserved Aug 16, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 30, 2014
GHSA-8W94-CF6G-C8MG