CVE-2019-13139OS Command Injection in Docker

Severity
8.4HIGHNVD
OSV9.8
EPSS
0.5%
top 32.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 22
Latest updateMay 24

Description

In Docker before 18.09.4, an attacker who is capable of supplying or manipulating the build path for the "docker build" command would be able to gain command execution. An issue exists in the way "docker build" processes remote git URLs, and results in command injection into the underlying "git clone" command, leading to code execution in the context of the user executing the "docker build" command. This occurs because git ref can be misinterpreted as a flag.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.5 | Impact: 5.9

Affected Packages2 packages

NVDdocker/docker< 18.09.4
Ubuntulibsndfile_project/libsndfile< 1.0.25-10ubuntu0.16.04.3+1

Patches

🔴Vulnerability Details

4
GHSA
GHSA-33j8-c2xf-8225: In Docker before 182022-05-24
OSV
libsndfile vulnerabilities2021-01-26
OSV
CVE-2019-13139: In Docker before 182019-08-22
CVEList
CVE-2019-13139: In Docker before 182019-08-22

📋Vendor Advisories

3
Microsoft
In Docker before 18.09.4 an attacker who is capable of supplying or manipulating the build path for the "docker build" command would be able to gain command execution. An issue exists in the way "dock2019-08-13
Red Hat
docker: command injection due to a missing validation of the git ref command2019-03-26
Debian
CVE-2019-13139: docker.io - In Docker before 18.09.4, an attacker who is capable of supplying or manipulatin...2019

💬Community

6
Bugzilla
CVE-2019-13139 docker: command injection due to a missing validation of the git ref command [epel-6]2019-07-30
Bugzilla
CVE-2019-13139 docker: command injection due to a missing validation of the git ref command [fedora-all]2019-07-30
Bugzilla
CVE-2019-13139 docker: command injection due to a missing validation of the git ref command [openstack-rdo]2019-07-23
Bugzilla
CVE-2019-13139 docker: command injection due to a missing validation of the git ref command [fedora-all]2019-07-23
Bugzilla
CVE-2019-13139 docker: command injection due to a missing validation of the git ref command2019-07-23