Vulnerabilities > Boot2Docker

DATE CVE VULNERABILITY TITLE RISK
2018-02-06 CVE-2014-5280 Cross-Site Request Forgery (CSRF) vulnerability in Boot2Docker
boot2docker 1.2 and earlier allows attackers to conduct cross-site request forgery (CSRF) attacks by leveraging Docker daemons enabling TCP connections without TLS authentication.
network
low complexity
boot2docker CWE-352
8.8
2018-02-06 CVE-2014-5279 Improper Access Control vulnerability in Boot2Docker
The Docker daemon managed by boot2docker 1.2 and earlier improperly enables unauthenticated TCP connections by default, which makes it easier for remote attackers to gain privileges or execute arbitrary code from children containers.
network
low complexity
boot2docker CWE-284
8.8