CVE-2019-13509

In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docker stack deploy is run to redeploy a stack that includes (non external) secrets. It potentially applies to other API users of the stack API if they resend the secret.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:docker:docker:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:1:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:2:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:3:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:4:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:5:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:6:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:7:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:8:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:1:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:10:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:11:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:12:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:13:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:15:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:16:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:17:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:18:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:19:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:2:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:20:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:21:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:22:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:3:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:4:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:5:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:6:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:7:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:8:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:9:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:1:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:2:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:3:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:4:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:5:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:6:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:7:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:8:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:9:*:*:enterprise:*:*:*

Configuration 2 (hide)

cpe:2.3:a:docker:docker:*:*:*:*:community:*:*:*

History

21 Nov 2024, 04:25

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00084.html - () http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00084.html -
References () http://www.securityfocus.com/bid/109253 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/109253 - Third Party Advisory, VDB Entry
References () https://docs.docker.com/engine/release-notes/ - Release Notes, Vendor Advisory () https://docs.docker.com/engine/release-notes/ - Release Notes, Vendor Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N674WD3OBDPHLWY6EABRHQH5ON6SUJBU/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N674WD3OBDPHLWY6EABRHQH5ON6SUJBU/ -
References () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PFFBVE7O73TAVY2BCWXSA2OOSLJVCPXC/ - () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PFFBVE7O73TAVY2BCWXSA2OOSLJVCPXC/ -
References () https://seclists.org/bugtraq/2019/Sep/21 - () https://seclists.org/bugtraq/2019/Sep/21 -
References () https://security.netapp.com/advisory/ntap-20190828-0003/ - () https://security.netapp.com/advisory/ntap-20190828-0003/ -
References () https://www.debian.org/security/2019/dsa-4521 - () https://www.debian.org/security/2019/dsa-4521 -

07 Nov 2023, 03:03

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N674WD3OBDPHLWY6EABRHQH5ON6SUJBU/', 'name': 'FEDORA-2019-4bed83e978', 'tags': [], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PFFBVE7O73TAVY2BCWXSA2OOSLJVCPXC/', 'name': 'FEDORA-2019-5b54793a4a', 'tags': [], 'refsource': 'FEDORA'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N674WD3OBDPHLWY6EABRHQH5ON6SUJBU/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PFFBVE7O73TAVY2BCWXSA2OOSLJVCPXC/ -

Information

Published : 2019-07-18 16:15

Updated : 2024-11-21 04:25


NVD link : CVE-2019-13509

Mitre link : CVE-2019-13509

CVE.ORG link : CVE-2019-13509


JSON object : View

Products Affected

docker

  • docker
CWE
CWE-532

Insertion of Sensitive Information into Log File