CVE-2019-13509

In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docker stack deploy is run to redeploy a stack that includes (non external) secrets. It potentially applies to other API users of the stack API if they resend the secret.
Configurations

Configuration 1

cpe:2.3:a:docker:docker:17.03.2:8:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:7:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:1:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:2:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:3:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:4:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:5:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:6:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:7:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:8:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:9:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:10:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:11:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:12:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:13:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:15:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:16:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:17:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:18:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:19:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:20:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:21:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.06.2:22:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:1:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:2:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:3:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:4:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:5:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:6:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:7:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:8:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:18.03.1:9:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:6:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:5:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:4:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:3:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:2:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:17.03.2:1:*:*:enterprise:*:*:*
cpe:2.3:a:docker:docker:*:*:*:*:community:*:*:*

Information

Published : 2019-07-18 04:15

Updated : 2019-08-27 05:15


NVD link : CVE-2019-13509

Mitre link : CVE-2019-13509

Products Affected
No products.
CWE
CWE-532

Insertion of Sensitive Information into Log File