util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, constructed with an empty first argument in an ioutil.TempDir call.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/moby/moby(Go) | 0 | 19.03.9 | N/A |
| github.com/docker/docker(Go) | 0 | 19.03.9 | N/A |
CVSS Metrics