CVE-2019-13139

Source
https://cve.org/CVERecord?id=CVE-2019-13139
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-13139.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-13139
Downstream
Related
Published
2019-08-22T20:15:12.003Z
Modified
2026-02-11T11:44:55.389822Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In Docker before 18.09.4, an attacker who is capable of supplying or manipulating the build path for the "docker build" command would be able to gain command execution. An issue exists in the way "docker build" processes remote git URLs, and results in command injection into the underlying "git clone" command, leading to code execution in the context of the user executing the "docker build" command. This occurs because git ref can be misinterpreted as a flag.

References

Affected packages

Git / github.com/docker/docker

Affected ranges

Type
GIT
Repo
https://github.com/docker/docker
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-13139.json"