PT-2025-18192 · Docker · Docker Desktop

CVE-2025-3911

·

Published

2025-04-29

·

Updated

2025-04-30

CVSS v4.0

5.2

Medium

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Docker Desktop versions prior to 4.41.0
Description The issue concerns the recording of environment variables in Docker Desktop application logs, which could lead to unintentional disclosure of sensitive information such as API keys and passwords. A malicious actor with read access to these logs could obtain sensitive credentials information and use it to gain unauthorized access to other systems.
Recommendations For Docker Desktop versions prior to 4.41.0, update to version 4.41.0 or later to prevent the logging of environment variables set by the user. As a temporary workaround, consider restricting access to the application logs to minimize the risk of exploitation.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-3911

Affected Products

Docker Desktop