PT-2026-3491 · Tugtainer · Tugtainer

Thxtech

·

Publicado

2026-01-19

·

Atualizado

2026-01-20

·

CVE-2026-23846

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Tugtainer versions prior to 1.16.1
Description Tugtainer is a self-hosted application designed for automating updates of Docker containers. Prior to version 1.16.1, the password authentication process transmits passwords through URL query parameters rather than utilizing the HTTP request body. This practice results in passwords being recorded in server access logs and potentially exposed via browser history, Referer headers, and proxy logs.
Recommendations Update Tugtainer to version 1.16.1 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-23846
GHSA-F2QF-F544-XM4P

Produtos afetados

Tugtainer