PT-2025-18194 · Docker · Docker Desktop

Published

2025-04-29

·

Updated

2025-05-06

·

CVE-2025-4095

CVSS v4.0

4.3

Medium

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Docker Desktop (affected versions not specified)
Description The issue concerns a security feature called Registry Access Management (RAM) that allows administrators to restrict access to only allowed registries. However, when a MacOS configuration profile is used to enforce organization sign-in, the RAM policies are not applied. This would allow Docker Desktop users to pull down unapproved and potentially malicious images from any registry.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-4095

Affected Products

Docker Desktop