In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docker stack deploy is run to redeploy a stack that includes (non external) secrets. It potentially applies to other API users of the stack API if they resend the secret.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "17.03.2-1"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.03.2:1:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.03.2-2"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.03.2:2:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.03.2-3"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.03.2:3:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.03.2-4"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.03.2:4:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.03.2-5"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.03.2:5:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.03.2-6"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.03.2:6:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.03.2-7"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.03.2:7:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.03.2-8"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.03.2:8:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-10"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:10:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-11"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:11:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-12"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:12:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-13"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:13:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-15"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:15:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-16"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:16:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-17"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:17:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-18"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:18:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-19"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:19:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-1"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:1:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-20"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:20:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-21"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:21:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-22"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:22:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-2"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:2:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-3"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:3:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-4"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:4:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-5"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:5:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-6"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:6:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-7"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:7:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-8"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:8:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "17.06.2-9"
}
],
"cpe": "cpe:2.3:a:docker:docker:17.06.2:9:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "18.03.1-1"
}
],
"cpe": "cpe:2.3:a:docker:docker:18.03.1:1:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "18.03.1-2"
}
],
"cpe": "cpe:2.3:a:docker:docker:18.03.1:2:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "18.03.1-3"
}
],
"cpe": "cpe:2.3:a:docker:docker:18.03.1:3:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "18.03.1-4"
}
],
"cpe": "cpe:2.3:a:docker:docker:18.03.1:4:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "18.03.1-5"
}
],
"cpe": "cpe:2.3:a:docker:docker:18.03.1:5:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "18.03.1-6"
}
],
"cpe": "cpe:2.3:a:docker:docker:18.03.1:6:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "18.03.1-7"
}
],
"cpe": "cpe:2.3:a:docker:docker:18.03.1:7:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "18.03.1-8"
}
],
"cpe": "cpe:2.3:a:docker:docker:18.03.1:8:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "18.03.1-9"
}
],
"cpe": "cpe:2.3:a:docker:docker:18.03.1:9:*:*:enterprise:*:*:*",
"source": "CPE_FIELD"
}
]
}{
"extracted_events": [
{
"introduced": "18.09.0"
},
{
"fixed": "18.09.8"
},
{
"introduced": "0"
},
{
"fixed": "18.09.8"
}
],
"cpe": [
"cpe:2.3:a:docker:docker:*:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:docker:docker:*:*:*:*:community:*:*:*"
],
"source": "CPE_FIELD"
}