← Back

Tugtainer

tugtainer

Vendor: Quenary • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Quenary
1Tugtainer
Jun 17, 2026
Jan 19, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.16.1, the password authentication mechanism transmits passwords via URL query parameters instead of the HTTP request body...Show more
Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.16.1, the password authentication mechanism transmits passwords via URL query parameters instead of the HTTP request body. This causes passwords to be logged in server access logs and potentially exposed through browser history, Referer headers, and proxy logs. Version 1.16.1 patches the issue.Show less
1Quenary
1Tugtainer
Jun 17, 2026
Dec 29, 2025
8.1 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary arguments can be injected in tugtainer-agent `POST api/command/run`. Version 1.15.1 fixes the issue.