Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-8867.json"