PT-2025-9918 · Docker · Docker Desktop

Publicado

2025-03-06

·

Atualizado

2025-03-07

·

CVE-2025-1696

CVSS v4.0

5.2

Média

VetorAV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Docker Desktop versions prior to 4.39.0
Description A vulnerability exists that could lead to the unintentional disclosure of sensitive information via application logs. In affected versions, proxy configuration data—potentially including sensitive details—was written to log files in clear text whenever an HTTP GET request was made through a proxy. An attacker with read access to these logs could obtain the proxy information and leverage it for further attacks or unauthorized access.
Recommendations For versions prior to 4.39.0, update to version 4.39.0 or later to mitigate the risk of sensitive information disclosure.

Correção

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-1696

Produtos afetados

Docker Desktop