It was discovered that Docker could be made to expose sensitive information
when processing URLs in container image manifests. A remote attacker could use
this to trick the user and obtain the user's registry credentials
(CVE-2020-15157).
- https://bugs.mageia.org/show_bug.cgi?id=27437
- https://www.openwall.com/lists/oss-security/2020/10/15/1
- https://ubuntu.com/security/notices/USN-4589-2
- https://www.cve.org/CVERecord?id=CVE-2020-15157
- 7/core/docker-18.09.9-1.2.mga7
Get the latest Linux and open source security news straight to your inbox.