PT-2025-9918 · Docker · Docker Desktop
Published
2025-03-06
·
Updated
2025-03-07
·
CVE-2025-1696
CVSS v4.0
5.2
Medium
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Docker Desktop versions prior to 4.39.0
Description
A vulnerability exists that could lead to the unintentional disclosure of sensitive information via application logs. In affected versions, proxy configuration data—potentially including sensitive details—was written to log files in clear text whenever an HTTP GET request was made through a proxy. An attacker with read access to these logs could obtain the proxy information and leverage it for further attacks or unauthorized access.
Recommendations
For versions prior to 4.39.0, update to version 4.39.0 or later to mitigate the risk of sensitive information disclosure.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docker Desktop