PT-2025-18192 · Docker · Docker Desktop

Published

2025-04-29

·

Updated

2025-04-30

·

CVE-2025-3911

CVSS v4.0

5.2

Medium

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Docker Desktop versions prior to 4.41.0
Description The issue concerns the recording of environment variables in Docker Desktop application logs, which could lead to unintentional disclosure of sensitive information such as API keys and passwords. A malicious actor with read access to these logs could obtain sensitive credentials information and use it to gain unauthorized access to other systems.
Recommendations For Docker Desktop versions prior to 4.41.0, update to version 4.41.0 or later to prevent the logging of environment variables set by the user. As a temporary workaround, consider restricting access to the application logs to minimize the risk of exploitation.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2025-3911

Affected Products

Docker Desktop