PatchSiren cyber security CVE debrief
CVE-2016-7569 Docker2aci Project CVE debrief
CVE-2016-7569 is a directory traversal flaw in docker2aci that can let a crafted image write to unintended files. NVD maps the issue to CWE-22 and rates it medium severity, with impact concentrated on integrity. The vulnerable range is through version 0.12.3, and the fix is associated with release v0.13.0.
- Vendor
- Docker2aci Project
- Product
- Docker2aci
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-27
- Advisory updated
- 2026-05-13
Who should care
Teams that use docker2aci to process container images, especially where images may come from less trusted sources or automated build pipelines, should treat this as a file-write integrity risk and verify they are not running affected versions.
Technical summary
The vulnerability is described as a directory traversal condition in embedded layer data within an image, where dot-dot path elements can be used to escape intended extraction paths. NVD classifies the weakness as CWE-22 and lists the CVSS v3.0 vector as AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N, indicating a high integrity impact with no confidentiality or availability impact scored. The affected version range in NVD ends at 0.12.3, with v0.13.0 referenced as the corrective release.
Defensive priority
Medium. This is not a remote code execution issue, but arbitrary file write conditions can still be serious in build, packaging, or extraction workflows that handle untrusted input.
Recommended defensive actions
- Upgrade docker2aci to v0.13.0 or later.
- Audit any systems that process untrusted or externally supplied container images with docker2aci.
- Review downstream pipelines for unexpected file modifications or extraction behavior.
- Restrict who can supply images to affected workflows until remediation is complete.
- Validate that deployment artifacts are sourced from fixed, trusted builds rather than affected versions.
Evidence notes
Source corpus ties the issue to CWE-22 and a vulnerable version range through 0.12.3, with references to OSS Security mailing list posts, a GitHub issue, and the v0.13.0 release. The official NVD entry also provides the CVSS v3.0 vector AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N. The public disclosure trail in the supplied references dates to 2016-09-28, while the CVE record was published on 2017-01-27.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-7569 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-7569
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-7569 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-7569
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/appc/docker2aci/issues/201
[email protected] - Issue Tracking, Patch, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/appc/docker2aci/releases/tag/v0.13.0
[email protected] - Issue Tracking, Patch, Release Notes, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.