System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc.
A malicious actor with read access to these logs could obtain secrets and further use them to gain unauthorized access to other systems. Starting with version 4.43.0 Docker Desktop no longer logs system environment variables as part of diagnostics log collection.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 03 Jul 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious actor with read access to these logs could obtain secrets and further use them to gain unauthorized access to other systems. Starting with version 4.43.0 Docker Desktop no longer logs system environment variables as part of diagnostics log collection. | |
Title | Exposure of system environment variables in Docker Desktop diagnostic logs | |
Weaknesses | CWE-532 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Docker
Published: 2025-07-03T10:03:27.155Z
Updated: 2025-07-04T03:55:30.300Z
Reserved: 2025-06-24T20:47:44.847Z
Link: CVE-2025-6587

Updated: 2025-07-03T13:19:50.770Z

Status : Awaiting Analysis
Published: 2025-07-03T10:15:37.773
Modified: 2025-07-03T15:13:53.147
Link: CVE-2025-6587

No data.