Quenary/tugtainer

Quenary/tugtainer

Releases76
Frequency3 days 9 hours
Last Release
Stars1.47K
An application for automated Docker container updates with a web UI

CVE History

CVEPublishedCVSS v3CVSS v2
8.1 HIGH

Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.16.1, the password authentication mechanism transmits passwords via URL query parameters instead of the HTTP request body. This causes passwords to be logged in server access logs and potentially exposed through browser history, Referer headers, and proxy logs. Version 1.16.1 patches the issue.

9.8 CRITICAL

Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary arguments can be injected in tugtainer-agent `POST api/command/run`. Version 1.15.1 fixes the issue.