USN-5134-1: Docker vulnerability

Publication date

9 November 2021

Overview

Docker could be made to expose sensitive information over the network.


Packages

Details

An information disclosure issue was discovered in the command line interface
of Docker. A misconfigured credential store could result in supplied
credentials being leaked to the public registry, when using the docker login
command with a private registry.

An information disclosure issue was discovered in the command line interface
of Docker. A misconfigured credential store could result in supplied
credentials being leaked to the public registry, when using the docker login
command with a private registry.

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
21.10 impish docker.io –  20.10.7-0ubuntu5.1
21.04 hirsute docker.io –  20.10.7-0ubuntu5~21.04.2
20.04 focal docker.io –  20.10.7-0ubuntu5~20.04.2
18.04 bionic docker.io –  20.10.7-0ubuntu5~18.04.3

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›