rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
https://github.com/rakibtg/docker-web-gui/issues/23 | third party advisory |
https://github.com/rakibtg/docker-web-gui/commit/79cdc41809f2030fce21a1109898bd79e4190661 | third party advisory patch |
https://www.docker.com/legal/trademark-guidelines | third party advisory |
http://packetstormsecurity.com/files/163416/Docker-Dashboard-Remote-Command-Execution.html | vdb entry third party advisory |