CVE-2014-5280: BOOT2DOCKER

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

boot2docker 1.2 and earlier allows attackers to conduct cross-site request forgery (CSRF) attacks by leveraging Docker daemons enabling TCP connections without TLS authentication.

Affected products

Published 2018-02-06. Last modified 2026-06-17.