CVE-2014-5280: BOOT2DOCKER
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
boot2docker 1.2 and earlier allows attackers to conduct cross-site request forgery (CSRF) attacks by leveraging Docker daemons enabling TCP connections without TLS authentication.
Affected products
- BOOT2DOCKER BOOT2DOCKER: up to and including 1.2.0
Published 2018-02-06. Last modified 2026-06-17.