DEBIAN-CVE-2019-13139

Advisory lineage Upstream: 1 Downstream: 1
Upstream
Downstream
Published: 22 Aug 2019, 20:15
Last modified:28 Apr 2026, 20:20

Vulnerability Summary

Overall Risk (default)
medium
34/100
CVSS Score
8.4 HIGH
3.0 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

22 Aug 2019, 20:15
Published
Vulnerability first disclosed
28 Apr 2026, 20:20
Last Modified
Vulnerability information updated

Description

In Docker before 18.09.4, an attacker who is capable of supplying or manipulating the build path for the "docker build" command would be able to gain command execution. An issue exists in the way "docker build" processes remote git URLs, and results in command injection into the underlying "git clone" command, leading to code execution in the context of the user executing the "docker build" command. This occurs because git ref can be misinterpreted as a flag.

CVSS Metrics

  • v3.0HIGHScore: 8.4CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Systems

  • debiandocker.io

    < 18.09.1+dfsg1-8 | < 18.09.1+dfsg1-8 | < 18.09.1+dfsg1-8 | < 18.09.1+dfsg1-8

References (1)