PT-2025-25764 · Docker+3 · Docker+4
Andres-Portainer
·
Published
2025-06-17
·
Updated
2025-07-07
·
CVE-2025-49593
CVSS v2.0
8.3
High
| Vector | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Portainer Community Edition versions prior to 2.31.0 (STS) and prior to 2.27.7 (LTS)
Description
The issue affects a lightweight service delivery platform for containerized applications, allowing management of Docker, Swarm, Kubernetes, and ACI environments. If an administrator is convinced to register a malicious container registry, or an existing registry is taken over, HTTP Headers may be leaked, including registry authentication credentials or session tokens.
Recommendations
For versions prior to 2.31.0 (STS) and prior to 2.27.7 (LTS), update to version 2.31.0 (STS) or 2.27.7 (LTS) to resolve the issue. As a temporary workaround, consider restricting the registration of new container registries and monitoring existing ones for suspicious activity. Avoid using vulnerable registries until the issue is resolved.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aci
Docker
Kubernetes
Portainer Community Edition
Red Os