Credential Leakage in Docker CLI Plugin Buildx by Docker
CVE-2025-0495

4.1MEDIUM

Key Information:

Vendor

Docker

Status
Vendor
CVE Published:
17 March 2025

What is CVE-2025-0495?

The Docker CLI plugin Buildx has a vulnerability that allows secure credential values to be captured in OpenTelemetry traces when user inputs are provided directly as attribute values in cache configuration settings. This can lead to unintended exposure of sensitive information through the command arguments and flags traced in OpenTelemetry. Notably, this issue does not affect secrets transmitted to the GitHub cache backend via environment variables or registry authentication.

Affected Version(s)

buildx 0 <= 0.21.2

References

CVSS V4

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.