CVE-2021-27886
Dashboard / Vulnerabilities / CVE-2021-27886
CVE-2021-27886
Published: 2 Mar 2021Last Modified: 8 Jul 2026
Summary:
Details: rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product.
References: http://packetstormsecurity.com/files/163416/Docker-Dashboard-Remote-Command-Execution.html, https://github.com/rakibtg/docker-web-gui/issues/23, https://www.docker.com/legal/trademark-guidelines, https://github.com/rakibtg/docker-web-gui/commit/79cdc41809f2030fce21a1109898bd79e4190661
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
