PT-2019-3465 · Docker+1 · Docker Ee+4

Published

2019-07-18

·

Updated

2026-05-18

·

CVE-2019-13509

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Docker CE versions prior to 18.09.8 Docker EE versions prior to 17.06.2-ee-23 Docker EE versions prior to 18.03.1-ee-10 Docker EE 18.x versions prior to 18.03.1-ee-10
Description The issue is related to the potential disclosure of secrets through log files when Docker Engine is run in debug mode. This can occur when docker stack deploy is used to redeploy a stack that includes non-external secrets. The problem may also apply to other API users of the stack API if they resend the secret. The vulnerability could allow a remote attacker to gain unauthorized access to information.
Recommendations For Docker CE versions prior to 18.09.8, update to version 18.09.8 or later. For Docker EE versions prior to 17.06.2-ee-23, update to version 17.06.2-ee-23 or later. For Docker EE versions prior to 18.03.1-ee-10, update to version 18.03.1-ee-10 or later. For Docker EE 18.x versions prior to 18.03.1-ee-10, update to version 18.03.1-ee-10 or later. As a temporary workaround, consider disabling debug mode for Docker Engine to minimize the risk of secret disclosure.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03639
CLEANSTART-2026-BK59402
CLEANSTART-2026-BN11148
CLEANSTART-2026-GY69323
CLEANSTART-2026-HI89495
CLEANSTART-2026-HL71566
CLEANSTART-2026-JD48541
CLEANSTART-2026-OS18490
CLEANSTART-2026-SB85645
CLEANSTART-2026-SP51034
CLEANSTART-2026-TD34476
CLEANSTART-2026-XL45869
CLEANSTART-2026-YB44027
CLEANSTART-2026-ZM20570
CVE-2019-13509
DSA-4521-1
GHSA-J249-GHV5-7MXV
OPENSUSE-SU-2019:2021-1
OPENSUSE-SU-2019_2021-1
OPENSUSE-SU-2024:10722-1
OPENSUSE-SU-2025:15589-1
SUSE-SU-2019:2117-1
SUSE-SU-2019:2119-1
SUSE-SU-2025:03540-1
SUSE-SU-2025:03545-1

Affected Products

Docker
Docker Ce
Docker Ee
Docker Engine
Suse