CVE-2015-3631
MediumAdvisory
Published 18 May 2015In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.006
- 45th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 68
- of 17,781 indexed, latest versions
- Container images
- 63
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Arbitrary File Override in Docker Engine
Carried by container images the latest versions of 68 of 17,781 indexed charts deploy, on 63 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| docker.iodeb | 1.0.1~dfsg1-0ubuntu1~ubuntu0.14.04.1 | 1.6.2~dfsg1-1ubuntu4~14.04.1 | 1 |
| github.com/ | v0.0.0-20180620051407-e2593239d949, v0.7.3-0.20190327010347-be7ac8be2ae0, v1.4.2-0.20190924003213-a8608b5b67c7, v1.4.2-0.20191121165722-d1d5f6476656+2 more | 1.6.1 | 62 |
- OSV records
- GHSA-v4h8-794j-g8mmUBUNTU-CVE-2015-3631
- Also known as
- GO-2022-0708
Charts affected
68 by stars
Container images carrying it
63 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 198db44fabb5 | github.com/ | 1.6.1 | 1 |
| ghcr.io/ | 66bbaf95a123 | github.com/ | 1.6.1 | 1 |
| ghcr.io/ | e918014fb8d3 | github.com/ | 1.6.1 | 1 |
| ghcr.io/ | c4f6c03af5d3 | github.com/ | 1.6.1 | 1 |
| ghcr.io/ | 64f5eb7a398b | github.com/ | 1.6.1 | 1 |
| ghcr.io/ | f36c423cd259 | github.com/ | 1.6.1 | 1 |
| ghcr.io/ | b2666ffcbad8 | github.com/ | 1.6.1 | 1 |
| ghcr.io/ | 9affab218351 | github.com/ | 1.6.1 | 1 |
| ghcr.io/ | 8f1bbd5cda85 | github.com/ | 1.6.1 | 1 |
| quay.io/ | 9663f06adcb1 | github.com/ | 1.6.1 | 1 |
| quay.io/ | e045b26eb6df | github.com/ | 1.6.1 | 1 |
| quay.io/ | 6722d5041b47 | github.com/ | 1.6.1 | 1 |
| quay.io/ | 6ba82beff18e | github.com/ | 1.6.1 | 1 |