Information disclosure in Docker CLI - CVE-2021-41092
Published: June 15, 2022
Vulnerability identifier: #VU64417
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-41092
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
Docker CLI
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE MicroOS
SUSE Enterprise Storage
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
openEuler
Fedora
Spectrum Discover
Dell Secure Connect Gateway
IBM Robotic Process Automation
IBM Cloud Pak System
runc
runc-debuginfo
containerd
docker-engine
docker.io (Ubuntu package)
docker
moby-engine
docker-debuginfo
docker-fish-completion
docker-bash-completion
SCALANCE LPE9403
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE MicroOS
SUSE Enterprise Storage
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
openEuler
Fedora
Spectrum Discover
Dell Secure Connect Gateway
IBM Robotic Process Automation
IBM Cloud Pak System
runc
runc-debuginfo
containerd
docker-engine
docker.io (Ubuntu package)
docker
moby-engine
docker-debuginfo
docker-fish-completion
docker-bash-completion
SCALANCE LPE9403
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
How to mitigate CVE-2021-41092
Install updates from vendor's website.
Docker CLI - update to 20.10.9
Spectrum Discover - update to 2.0.4.5
Dell Secure Connect Gateway - update to 5.12.00.10
IBM Robotic Process Automation - update to 21.0.2.3
runc - addressed in versions 1.0.2-16.14.1, 1.0.2-23.1
runc-debuginfo - addressed in versions 1.0.2-16.14.1, 1.0.2-23.1
containerd - addressed in versions 1.4.11-16.45.1, 1.4.11-56.1, 1.4.12-16.49.1, 1.4.12-60.1
containerd - addressed in versions 1.5.7-1.fc34, 1.5.7-1.fc35
SCALANCE LPE9403 - update to 2.0
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
docker-engine - update to 18.09.0-238
docker.io (Ubuntu package) - addressed in versions 20.10.7-0ubuntu5.1, 20.10.7-0ubuntu5~18.04.3, 20.10.7-0ubuntu5~20.04.2, 20.10.7-0ubuntu5~21.04.2
docker - update to 20.10.7-3.71
moby-engine - addressed in versions 20.10.9-1.fc34, 20.10.9-1.fc35
docker-debuginfo - addressed in versions 20.10.12_ce-98.75.1, 20.10.12_ce-159.1
docker - addressed in versions 20.10.12_ce-98.75.1, 20.10.12_ce-159.1
docker-fish-completion - update to 20.10.12_ce-159.1
docker-bash-completion - update to 20.10.12_ce-159.1
Spectrum Discover - update to 2.0.4.5
Dell Secure Connect Gateway - update to 5.12.00.10
IBM Robotic Process Automation - update to 21.0.2.3
runc - addressed in versions 1.0.2-16.14.1, 1.0.2-23.1
runc-debuginfo - addressed in versions 1.0.2-16.14.1, 1.0.2-23.1
containerd - addressed in versions 1.4.11-16.45.1, 1.4.11-56.1, 1.4.12-16.49.1, 1.4.12-60.1
containerd - addressed in versions 1.5.7-1.fc34, 1.5.7-1.fc35
SCALANCE LPE9403 - update to 2.0
Dell EMC Unity Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.0.0.5.173
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.0.0.5.173
docker-engine - update to 18.09.0-238
docker.io (Ubuntu package) - addressed in versions 20.10.7-0ubuntu5.1, 20.10.7-0ubuntu5~18.04.3, 20.10.7-0ubuntu5~20.04.2, 20.10.7-0ubuntu5~21.04.2
docker - update to 20.10.7-3.71
moby-engine - addressed in versions 20.10.9-1.fc34, 20.10.9-1.fc35
docker-debuginfo - addressed in versions 20.10.12_ce-98.75.1, 20.10.12_ce-159.1
docker - addressed in versions 20.10.12_ce-98.75.1, 20.10.12_ce-159.1
docker-fish-completion - update to 20.10.12_ce-159.1
docker-bash-completion - update to 20.10.12_ce-159.1
External References
- https://github.com/docker/cli/commit/893e52cf4ba4b048d72e99748e0f86b2767c6c6b
- https://github.com/docker/cli/security/advisories/GHSA-99pg-grm5-qq3v
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZNFADTCHHYWVM6W4NJ6CB4FNFM2VMBIB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B5Q6G6I4W5COQE25QMC7FJY3I3PAYFBB/
- https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf
Related Security Bulletins
- Information disclosure in Docker CLI
- Multiple vulnerabilities in Siemens SCALANCE LPE9403
- SUSE update for containerd, docker, runc
- SUSE update for containerd, docker, runc
- Ubuntu update for docker.io
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Multiple vulnerabilities in IBM Spectrum Discover
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- SUSE update for containerd, docker
- SUSE update for containerd, docker
- Amazon Linux AMI update for docker
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT
- openEuler update for docker
- Fedora 35 update for containerd, moby-engine
- Fedora 34 update for containerd, moby-engine
- Information disclosure in IBM Cloud Pak System