Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-13139 PoC — Docker 命令注入漏洞

Source
Associated Vulnerability
Title:Docker 命令注入漏洞 (CVE-2019-13139)
Description:Docker是美国Docker公司的一款开源的应用容器引擎。该产品支持在Linux系统上创建一个容器(轻量级虚拟机)并部署和运行应用程序,以及通过配置文件实现应用程序的自动化安装、部署和升级。 Docker 18.09.4之前版本中‘docker build’处理远程git URL的方式存在命令注入漏洞。攻击者可利用该漏洞执行命令。
File Snapshot

# Docker build 漏洞导致命令执行 CVE-2019-13139 ## 漏洞描述 使用 `docker build` 命令构建本地镜像时,支持使用远程 url 参数作为构建环境,并且这 ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.