DEBIAN-CVE-2019-13139
Advisory lineage Upstream: 1 Downstream: 1
Upstream
Downstream
Published: 22 Aug 2019, 20:15
Last modified:28 Apr 2026, 20:20
Vulnerability Summary
Overall Risk (default)
medium
34/100 CVSS Score
8.4 HIGH
3.0 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
22 Aug 2019, 20:15
Published
Vulnerability first disclosed
28 Apr 2026, 20:20
Last Modified
Vulnerability information updated
Description
In Docker before 18.09.4, an attacker who is capable of supplying or manipulating the build path for the "docker build" command would be able to gain command execution. An issue exists in the way "docker build" processes remote git URLs, and results in command injection into the underlying "git clone" command, leading to code execution in the context of the user executing the "docker build" command. This occurs because git ref can be misinterpreted as a flag.
CVSS Metrics
- v3.0•HIGH•Score: 8.4CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- debian•docker.io
< 18.09.1+dfsg1-8 | < 18.09.1+dfsg1-8 | < 18.09.1+dfsg1-8 | < 18.09.1+dfsg1-8