Description
Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app-s openresty/http-includes/ git repository directory to the host and then interpolates their filenames, unescaped, into a single-quoted shell string that is later parsed by eval. A filename containing a single quote breaks the quoting and allows command substitution to execute arbitrary commands on the host as the dokku user during the app-s next deploy. This vulnerability is fixed in 0.38.2.
CVSS 9EPSS 0.27999999999999997%Risque 0.92
Voir la source- Publication
- 2026-06-26 17:16:33
- Versions concernées
- <0.38.2
- Type
- Application web
- Vecteur
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H