Skip to content

docker-cli CVE-2021-41092

Low
tjkirch published GHSA-vp43-f3pm-7jvp Oct 6, 2021

Package

docker-cli (bottlerocket)

Affected versions

< 1.3.0

Patched versions

1.3.0

Description

A bug was found in the Docker CLI where running docker login my-private-registry.example.com with a misconfigured configuration file (typically ~/.docker/config.json) listing a credsStore or credHelpers that could not be executed would result in any provided credentials being sent to registry-1.docker.io rather than the intended private registry.

Severity

Low

CVE ID

CVE-2021-41092

Weaknesses

No CWEs