First published: Thu Jul 18 2019(Updated: )
In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docker stack deploy is run to redeploy a stack that includes (non external) secrets. It potentially applies to other API users of the stack API if they resend the secret.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/docker/docker | <18.09.8 | 18.09.8 |
debian/docker.io | 18.09.1+dfsg1-7.1+deb10u3 20.10.5+dfsg1-1+deb11u2 20.10.24+dfsg1-1 20.10.25+dfsg1-2 | |
Docker | >=18.09.0<18.09.8 | |
Docker | =17.03.2-1 | |
Docker | =17.03.2-2 | |
Docker | =17.03.2-3 | |
Docker | =17.03.2-4 | |
Docker | =17.03.2-5 | |
Docker | =17.03.2-6 | |
Docker | =17.03.2-7 | |
Docker | =17.03.2-8 | |
Docker | =17.06.2-1 | |
Docker | =17.06.2-10 | |
Docker | =17.06.2-11 | |
Docker | =17.06.2-12 | |
Docker | =17.06.2-13 | |
Docker | =17.06.2-15 | |
Docker | =17.06.2-16 | |
Docker | =17.06.2-17 | |
Docker | =17.06.2-18 | |
Docker | =17.06.2-19 | |
Docker | =17.06.2-2 | |
Docker | =17.06.2-20 | |
Docker | =17.06.2-21 | |
Docker | =17.06.2-22 | |
Docker | =17.06.2-3 | |
Docker | =17.06.2-4 | |
Docker | =17.06.2-5 | |
Docker | =17.06.2-6 | |
Docker | =17.06.2-7 | |
Docker | =17.06.2-8 | |
Docker | =17.06.2-9 | |
Docker | =18.03.1-1 | |
Docker | =18.03.1-2 | |
Docker | =18.03.1-3 | |
Docker | =18.03.1-4 | |
Docker | =18.03.1-5 | |
Docker | =18.03.1-6 | |
Docker | =18.03.1-7 | |
Docker | =18.03.1-8 | |
Docker | =18.03.1-9 | |
Docker | <18.09.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13509 is a vulnerability in Docker CE and EE that allows secrets to be added to the debug log.
The severity of CVE-2019-13509 is high with a CVSS score of 7.5.
CVE-2019-13509 affects Docker CE and EE versions before 18.09.8, as well as Docker EE versions before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10.
To fix CVE-2019-13509, update Docker CE and EE to version 18.09.8 or higher.
More information about CVE-2019-13509 can be found at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-13509), [Docker Release Notes](https://docs.docker.com/engine/release-notes/18.09/), [GitHub Advisory](https://github.com/advisories/GHSA-j249-ghv5-7mxv).