[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Command injection vulnerability in Docker-ce and Docker-ee - CVE-2019-13139 (rpm)

ID: oval:org.secpod.oval:def:58212Date: (C)2019-10-09   (M)2023-11-10
Class: VULNERABILITYFamily: unix




The host is installed with Docker-ce or Docker-ee before 18.09.4 and is prone to a command injection vulnerability. A flaw is present in the application, which fails an issue in the way docker build processes remote git URLs. Successful exploitation allows attackers to cause code execution in the context of the user executing the docker build command.

Platform:
Linux
Product:
docker-ce
docker-ee
Reference:
CVE-2019-13139
CVE    1
CVE-2019-13139

© SecPod Technologies