CVE-2019-13509Log File Information Exposure in Docker Docker

Severity
7.5HIGHNVD
EPSS
1.6%
top 18.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 18
Latest updateMay 24

Description

In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docker stack deploy is run to redeploy a stack that includes (non external) secrets. It potentially applies to other API users of the stack API if they resend the secret.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDdocker/docker18.09.018.09.8+4

🔴Vulnerability Details

4
OSV
Secret insertion into debug log in Docker2022-05-24
GHSA
Secret insertion into debug log in Docker2022-05-24
OSV
CVE-2019-13509: In Docker CE and EE before 182019-07-18
CVEList
CVE-2019-13509: In Docker CE and EE before 182019-07-18

📋Vendor Advisories

3
Red Hat
docker: Docker Engine in debug mode may sometimes add secrets to the debug log leading to information disclosure2019-07-23
Microsoft
In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10) Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a s2019-07-09
Debian
CVE-2019-13509: docker.io - In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 an...2019

💬Community

3
Bugzilla
CVE-2019-13509 docker: Docker Engine in debug mode may sometimes add secrets to the debug log leading to information disclosure [epel-6]2019-07-23
Bugzilla
CVE-2019-13509 docker: Docker Engine in debug mode may sometimes add secrets to the debug log leading to information disclosure2019-07-23
Bugzilla
CVE-2019-13509 docker: Docker Engine in debug mode may sometimes add secrets to the debug log leading to information disclosure [fedora-all]2019-07-23
CVE-2019-13509 — Log File Information Exposure | cvebase