Closed
Description
In GitHub Security Advisory GHSA-j249-ghv5-7mxv, there is a vulnerability in the following Go packages or modules:
Unit | Fixed | Vulnerable Ranges |
---|---|---|
github.com/docker/docker | 18.09.8 | < 18.09.8 |
Cross references:
- Module github.com/docker/docker appears in issue x/vulndb: potential Go vuln in github.com/docker/docker: GHSA-44gg-pmqr-4669 #625 NOT_IMPORTABLE
- Module github.com/docker/docker appears in issue x/vulndb: potential Go vuln in github.com/docker/docker: GHSA-5qgp-p5jc-w2rm #630 NOT_IMPORTABLE
- Module github.com/docker/docker appears in issue x/vulndb: potential Go vuln in github.com/docker/docker: GHSA-8w94-cf6g-c8mg #636 NOT_IMPORTABLE
- Module github.com/docker/docker appears in issue x/vulndb: potential Go vuln in github.com/docker/docker: GHSA-997c-fj8j-rq5h #640 NOT_IMPORTABLE
- Module github.com/docker/docker appears in issue x/vulndb: potential Go vuln in github.com/docker/docker: GHSA-g44j-7vp3-68cv #647 NOT_IMPORTABLE
- Module github.com/docker/docker appears in issue x/vulndb: potential Go vuln in github.com/docker/docker: GHSA-g7v2-2qxx-wjrw #649 NOT_IMPORTABLE
- Module github.com/docker/docker appears in issue x/vulndb: potential Go vuln in github.com/docker/docker: GHSA-qmmc-jppf-32wv #705 NOT_IMPORTABLE
- Module github.com/docker/docker appears in issue x/vulndb: potential Go vuln in github.com/docker/docker: GHSA-wxj3-qwv4-cvfm #752 NOT_IMPORTABLE
See doc/triage.md for instructions on how to triage this report.
modules:
- module: github.com/docker/docker
versions:
- fixed: 18.09.8
packages:
- package: github.com/docker/docker
summary: Secret insertion into debug log in Docker
description: |-
In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23
and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add
secrets to the debug log. This applies to a scenario where docker stack deploy
is run to redeploy a stack that includes (non external) secrets. It potentially
applies to other API users of the stack API if they resend the secret.
cves:
- CVE-2019-13509
ghsas:
- GHSA-j249-ghv5-7mxv
references:
- web: https://nvd.nist.gov/vuln/detail/CVE-2019-13509
- web: https://docs.docker.com/engine/release-notes/18.09/
- advisory: https://github.com/advisories/GHSA-j249-ghv5-7mxv