PT-2025-9918 · Docker · Docker Desktop

Published

2025-03-06

·

Updated

2025-03-07

·

CVE-2025-1696

CVSS v4.0

5.2

Medium

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Docker Desktop versions prior to 4.39.0
Description A vulnerability exists that could lead to the unintentional disclosure of sensitive information via application logs. In affected versions, proxy configuration data—potentially including sensitive details—was written to log files in clear text whenever an HTTP GET request was made through a proxy. An attacker with read access to these logs could obtain the proxy information and leverage it for further attacks or unauthorized access.
Recommendations For versions prior to 4.39.0, update to version 4.39.0 or later to mitigate the risk of sensitive information disclosure.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-1696

Affected Products

Docker Desktop