docker security advisories
16 threat alerts tracking vulnerabilities and security advisories that affect docker products.
Vulnios monitors docker CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent docker security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2020-35195 — docker — haproxy_docker_image
The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank password for a root user. System using the haproxy docker container deployed by affected versions of the docke
criticalCVE-2020-35195Critical Vulnerability: CVE-2020-35184 — docker — composer_docker_image
The official composer docker images before 1.8.3 contain a blank password for a root user. System using the composer docker container deployed by affected versions of the docker image may allow a remo
criticalCVE-2020-35184Critical Vulnerability: CVE-2020-35467 — docker — docs
The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Docker Docs container may allow a remote attacker to achiev
criticalCVE-2020-35467Critical Vulnerability: CVE-2020-35197 — docker — memcached_docker_image
The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank password for a root user. System using the memcached docker container deployed by affected versions of the d
criticalCVE-2020-35197Critical Vulnerability: CVE-2020-35196 — docker — rabbitmq_docker_image
The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected v
criticalCVE-2020-35196Critical Vulnerability: CVE-2020-35185 — docker — ghost_alpine_docker_image
The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password for a root user. System using the ghost docker container deployed by affected versions of the docker im
criticalCVE-2020-35185Critical Vulnerability: CVE-2020-35186 — docker — adminer
The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed by affected versions of the docker image may allow
criticalCVE-2020-35186Critical Vulnerability: CVE-2020-29591 — docker — registry
Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of the registry container may allow a remote attacker
criticalCVE-2020-29591Critical Vulnerability: CVE-2020-29580 — docker — storm_docker_image
The official storm Docker images before 1.2.1 contain a blank password for a root user. Systems using the Storm Docker container deployed by affected versions of the Docker image may allow an remote a
criticalCVE-2020-29580Critical Vulnerability: CVE-2020-29575 — docker — elixir_alpine_docker_image
The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. Systems using the elixir Linux Docker container deployed by affected versions of the D
criticalCVE-2020-29575Critical Vulnerability: CVE-2020-29601 — docker — notary_docker_image
The official notary docker images before signer-0.6.1-1 contain a blank password for a root user. System using the notary docker container deployed by affected versions of the docker image may allow a
criticalCVE-2020-29601Critical Vulnerability: CVE-2020-29581 — docker — spiped_alpine_docker_image
The official spiped docker images before 1.5-alpine contain a blank password for a root user. Systems using the spiped docker container deployed by affected versions of the docker image may allow an r
criticalCVE-2020-29581Critical Vulnerability: CVE-2020-29389 — docker — crux_linux_docker_image
The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Linux Docker container deployed by affected versions of the Docker image may allow
criticalCVE-2020-29389Critical Vulnerability: CVE-2019-14271 — docker, debian — docker, debian_linux
In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the content
criticalCVE-2019-14271Critical Vulnerability: CVE-2015-9259 — docker — notary
In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment stating that it does. Even if a user creates a new root.json f
criticalCVE-2015-9259Critical Vulnerability: CVE-2014-0048 — docker, apache — docker, geode
An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways.
criticalCVE-2014-0048
Track docker exposure across your environment
Vulnios automatically cross-references your asset inventory against new docker CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan