CVE-2026-54636
- EPSS 0.27%
- Veröffentlicht 26.06.2026 16:23:58
- Zuletzt bearbeitet 29.06.2026 14:16:57
Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not limited to, > or...
CVE-2026-45405
- EPSS 0.29%
- Veröffentlicht 26.06.2026 16:23:05
- Zuletzt bearbeitet 26.06.2026 18:56:11
Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/zip archives into temporary directories without sanitizing member paths or preventing symlink traversal. GNU tar creates symlinks d...
CVE-2026-45406
- EPSS 0.28%
- Veröffentlicht 26.06.2026 16:22:17
- Zuletzt bearbeitet 26.06.2026 19:16:40
Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-includes/ git repository directory to the host and then interpolates their filenames, unescaped, into a single-quoted shell string ...
CVE-2026-45407
- EPSS 0.09%
- Veröffentlicht 26.06.2026 16:21:25
- Zuletzt bearbeitet 26.06.2026 19:16:40
Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch command, which applies the default umask of 0644. This pre-creation defeats the netrc binary's built-in 0600 permission setting, leavi...
- EPSS 0.23%
- Veröffentlicht 26.06.2026 16:19:56
- Zuletzt bearbeitet 26.06.2026 19:16:40
Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authenticated user pushes to a git remote with a crafted app name, the name is embedded unquoted into a bash p...