PT-2025-9918 · Docker · Docker Desktop
Publicado
2025-03-06
·
Atualizado
2025-03-07
·
CVE-2025-1696
CVSS v4.0
5.2
Média
| Vetor | AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Docker Desktop versions prior to 4.39.0
Description
A vulnerability exists that could lead to the unintentional disclosure of sensitive information via application logs. In affected versions, proxy configuration data—potentially including sensitive details—was written to log files in clear text whenever an HTTP GET request was made through a proxy. An attacker with read access to these logs could obtain the proxy information and leverage it for further attacks or unauthorized access.
Recommendations
For versions prior to 4.39.0, update to version 4.39.0 or later to mitigate the risk of sensitive information disclosure.
Correção
Insertion into Log File
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Docker Desktop