Lucene search

K
cve[email protected]CVE-2019-13509
HistoryJul 18, 2019 - 4:15 p.m.

CVE-2019-13509

2019-07-1816:15:11
CWE-532
web.nvd.nist.gov
150
docker
docker ce
docker ee
security
vulnerability
cve-2019-13509

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.5 High

AI Score

Confidence

High

0.042 Low

EPSS

Percentile

92.3%

In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docker stack deploy is run to redeploy a stack that includes (non external) secrets. It potentially applies to other API users of the stack API if they resend the secret.

Affected configurations

NVD
Node
dockerdockerRange18.09.018.09.8enterprise
OR
dockerdockerMatch17.03.21enterprise
OR
dockerdockerMatch17.03.22enterprise
OR
dockerdockerMatch17.03.23enterprise
OR
dockerdockerMatch17.03.24enterprise
OR
dockerdockerMatch17.03.25enterprise
OR
dockerdockerMatch17.03.26enterprise
OR
dockerdockerMatch17.03.27enterprise
OR
dockerdockerMatch17.03.28enterprise
OR
dockerdockerMatch17.06.21enterprise
OR
dockerdockerMatch17.06.210enterprise
OR
dockerdockerMatch17.06.211enterprise
OR
dockerdockerMatch17.06.212enterprise
OR
dockerdockerMatch17.06.213enterprise
OR
dockerdockerMatch17.06.215enterprise
OR
dockerdockerMatch17.06.216enterprise
OR
dockerdockerMatch17.06.217enterprise
OR
dockerdockerMatch17.06.218enterprise
OR
dockerdockerMatch17.06.219enterprise
OR
dockerdockerMatch17.06.22enterprise
OR
dockerdockerMatch17.06.220enterprise
OR
dockerdockerMatch17.06.221enterprise
OR
dockerdockerMatch17.06.222enterprise
OR
dockerdockerMatch17.06.23enterprise
OR
dockerdockerMatch17.06.24enterprise
OR
dockerdockerMatch17.06.25enterprise
OR
dockerdockerMatch17.06.26enterprise
OR
dockerdockerMatch17.06.27enterprise
OR
dockerdockerMatch17.06.28enterprise
OR
dockerdockerMatch17.06.29enterprise
OR
dockerdockerMatch18.03.11enterprise
OR
dockerdockerMatch18.03.12enterprise
OR
dockerdockerMatch18.03.13enterprise
OR
dockerdockerMatch18.03.14enterprise
OR
dockerdockerMatch18.03.15enterprise
OR
dockerdockerMatch18.03.16enterprise
OR
dockerdockerMatch18.03.17enterprise
OR
dockerdockerMatch18.03.18enterprise
OR
dockerdockerMatch18.03.19enterprise
Node
dockerdockerRange<18.09.8community

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.5 High

AI Score

Confidence

High

0.042 Low

EPSS

Percentile

92.3%