Red Hat Bugzilla – Bug 1063550
CVE-2014-0048 Docker: multiple files downloaded over HTTP and executed or used unsafely
Last modified: 2015-03-25 04:42:31 EDT
Kurt Seifried of the Red Hat Security Response Team reports: There are a number of programs and scripts in Docker that download content via HTTP and then execute the content or use it in other unsafe ways (e.g. signing keys used to further verify content that is downloaded and executed).
I can't speak for the build process etc. but monitoring 1.5 on the network I no longer detect any http traffic when issuing a docker pull. Anything else (e.g. bad Dockerfile hygeine) is a separate issue.