Описание
rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product.
rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-27886
- https://github.com/rakibtg/docker-web-gui/issues/23
- https://github.com/rakibtg/docker-web-gui/commit/79cdc41809f2030fce21a1109898bd79e4190661
- https://www.docker.com/legal/trademark-guidelines
- http://packetstormsecurity.com/files/163416/Docker-Dashboard-Remote-Command-Execution.html
Связанные уязвимости
CVSS3: 9.8
nvd
почти 5 лет назад
rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product.