In Docker CE and EE before 18.09.8 (as well as...
Vulnerability Description
In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docker stack deploy is run to redeploy a stack that includes (non external) secrets. It potentially applies to other API users of the stack API if they resend the secret.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-13509
Credits & Attribution
No credits recorded in the NVD database.
References
- https://docs.docker.com/engine/release-notes/
- http://www.securityfocus.com/bid/109253
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PFFBVE7O73TAVY2BCWXSA2OOSLJVCPXC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N674WD3OBDPHLWY6EABRHQH5ON6SUJBU/
- https://security.netapp.com/advisory/ntap-20190828-0003/
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00084.html
- https://www.debian.org/security/2019/dsa-4521
- https://seclists.org/bugtraq/2019/Sep/21
More from docker
View All →Affected Vendor
docker
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.