Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS05OXBnLWdybTUtcXEzds4AA84V
Docker CLI leaks private registry credentials to registry-1.docker.io
Impact
A bug was found in the Docker CLI where running docker login my-private-registry.example.com
with a misconfigured configuration file (typically ~/.docker/config.json
) listing a credsStore
or credHelpers
that could not be executed would result in any provided credentials being sent to registry-1.docker.io
rather than the intended private registry.
Patches
This bug has been fixed in Docker CLI 20.10.9. Users should update to this version as soon as possible.
Workarounds
Ensure that any configured credsStore
or credHelpers
entries in the configuration file reference an installed credential helper that is executable and on the PATH
.
For more information
If you have any questions or comments about this advisory:
- Open an issue
- Email us at [email protected] if you think you’ve found a security bug
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05OXBnLWdybTUtcXEzds4AA84V
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 6 months ago
Updated: 5 months ago
CVSS Score: 5.4
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N
Identifiers: GHSA-99pg-grm5-qq3v, CVE-2021-41092
References:
- https://github.com/docker/cli/security/advisories/GHSA-99pg-grm5-qq3v
- https://nvd.nist.gov/vuln/detail/CVE-2021-41092
- https://github.com/docker/cli/commit/893e52cf4ba4b048d72e99748e0f86b2767c6c6b
- https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf
- https://lists.fedoraproject.org/archives/list/[email protected]/message/B5Q6G6I4W5COQE25QMC7FJY3I3PAYFBB
- https://lists.fedoraproject.org/archives/list/[email protected]/message/ZNFADTCHHYWVM6W4NJ6CB4FNFM2VMBIB
- https://github.com/advisories/GHSA-99pg-grm5-qq3v
Blast Radius: 22.8
Affected Packages
go:github.com/docker/cli
Dependent packages: 6,302Dependent repositories: 16,666
Downloads:
Affected Version Ranges: < 20.10.9
Fixed in: 20.10.9
All affected versions: 20.10.0, 20.10.1, 20.10.2, 20.10.3, 20.10.4, 20.10.5, 20.10.6, 20.10.7, 20.10.8
All unaffected versions: 20.10.9, 20.10.10, 20.10.11, 20.10.12, 20.10.13, 20.10.14, 20.10.15, 20.10.16, 20.10.17, 20.10.18, 20.10.19, 20.10.20, 20.10.21, 20.10.22, 20.10.23, 20.10.24, 20.10.25, 20.10.26, 20.10.27, 23.0.0, 23.0.1, 23.0.2, 23.0.3, 23.0.4, 23.0.5, 23.0.6, 23.0.7, 23.0.8, 23.0.9, 23.0.10, 23.0.14, 23.0.15, 24.0.0, 24.0.1, 24.0.2, 24.0.3, 24.0.4, 24.0.5, 24.0.6, 24.0.7, 24.0.8, 24.0.9, 25.0.0, 25.0.1, 25.0.2, 25.0.3, 25.0.4, 25.0.5, 25.0.6, 26.0.0, 26.0.1, 26.0.2, 26.1.0, 26.1.1, 26.1.2, 26.1.3, 26.1.4, 26.1.5, 27.0.1, 27.0.2, 27.0.3, 27.1.0, 27.1.1, 27.1.2, 27.2.0, 27.2.1, 27.3.0, 27.3.1