PT-2025-18192 · Docker · Docker Desktop
Published
2025-04-29
·
Updated
2025-04-30
·
CVE-2025-3911
CVSS v4.0
5.2
Medium
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Docker Desktop versions prior to 4.41.0
Description
The issue concerns the recording of environment variables in Docker Desktop application logs, which could lead to unintentional disclosure of sensitive information such as API keys and passwords. A malicious actor with read access to these logs could obtain sensitive credentials information and use it to gain unauthorized access to other systems.
Recommendations
For Docker Desktop versions prior to 4.41.0, update to version 4.41.0 or later to prevent the logging of environment variables set by the user. As a temporary workaround, consider restricting access to the application logs to minimize the risk of exploitation.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docker Desktop