PYSEC-2014-80

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/docker-py/PYSEC-2014-80.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2014-80
Aliases
Published
2014-11-17T16:59:00Z
Modified
2024-08-21T15:26:43.035056Z
Summary
[none]
Details

Docker before 1.3.1 and docker-py before 0.5.3 fall back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic.

References

Affected packages

PyPI / docker-py

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.3

Affected versions

0.*

0.0.4
0.0.5
0.0.6
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.2.0
0.2.1
0.2.2
0.2.3
0.3.0
0.3.1
0.3.2
0.4.0
0.5.0
0.5.1
0.5.2