Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious actor with read access to these logs could obtain sensitive credentials information and further use it to gain unauthorized access to other systems. Starting with version 4.41.0, Docker Desktop no longer logs environment variables set by the user.
History

Tue, 29 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Apr 2025 17:30:00 +0000

Type Values Removed Values Added
Description Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious actor with read access to these logs could obtain sensitive credentials information and further use it to gain unauthorized access to other systems. Starting with version 4.41.0, Docker Desktop no longer logs environment variables set by the user.
Title Exposure in Docker Desktop logs of environment variables configured for running containers
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 5.2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Docker

Published: 2025-04-29T17:20:34.740Z

Updated: 2025-04-29T17:58:50.628Z

Reserved: 2025-04-23T20:43:14.232Z

Link: CVE-2025-3911

cve-icon Vulnrichment

Updated: 2025-04-29T17:58:46.165Z

cve-icon NVD

Status : Received

Published: 2025-04-29T18:15:44.370

Modified: 2025-04-29T18:15:44.370

Link: CVE-2025-3911

cve-icon Redhat

No data.