Credential Leakage in Docker CLI Plugin Buildx by Docker
CVE-2025-0495
4.1MEDIUM
What is CVE-2025-0495?
The Docker CLI plugin Buildx has a vulnerability that allows secure credential values to be captured in OpenTelemetry traces when user inputs are provided directly as attribute values in cache configuration settings. This can lead to unintended exposure of sensitive information through the command arguments and flags traced in OpenTelemetry. Notably, this issue does not affect secrets transmitted to the GitHub cache backend via environment variables or registry authentication.
Affected Version(s)
buildx 0 <= 0.21.2