docker docker CVE-2019-13139 is a vulnerability in Docker
Published on August 22, 2019

In Docker before 18.09.4, an attacker who is capable of supplying or manipulating the build path for the "docker build" command would be able to gain command execution. An issue exists in the way "docker build" processes remote git URLs, and results in command injection into the underlying "git clone" command, leading to code execution in the context of the user executing the "docker build" command. This occurs because git ref can be misinterpreted as a flag.

Vendor Advisory Vendor Advisory NVD


Products Associated with CVE-2019-13139

Want to know whenever a new CVE is published for Docker? stack.watch will email you.

 

Exploit Probability

EPSS
0.55%
Percentile
67.87%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.