Vulnerability Description
rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Docker Dashboard Project | Docker Dashboard | < 2021-02-28 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/163416/Docker-Dashboard-Remote-Command-ExecThird Party AdvisoryVDB Entry
- https://github.com/rakibtg/docker-web-gui/commit/79cdc41809f2030fce21a1109898bd7PatchThird Party Advisory
- https://github.com/rakibtg/docker-web-gui/issues/23Third Party Advisory
- https://www.docker.com/legal/trademark-guidelinesThird Party Advisory
- http://packetstormsecurity.com/files/163416/Docker-Dashboard-Remote-Command-ExecThird Party AdvisoryVDB Entry
- https://github.com/rakibtg/docker-web-gui/commit/79cdc41809f2030fce21a1109898bd7PatchThird Party Advisory
- https://github.com/rakibtg/docker-web-gui/issues/23Third Party Advisory
- https://www.docker.com/legal/trademark-guidelinesThird Party Advisory
FAQ
What is CVE-2021-27886?
CVE-2021-27886 is a vulnerability with a CVSS score of 9.8 (CRITICAL). rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, In...
How severe is CVE-2021-27886?
CVE-2021-27886 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-27886?
Check the references section above for vendor advisories and patch information. Affected products include: Docker Dashboard Project Docker Dashboard.