Sensitive Information Exposure in Docker Desktop by Docker
CVE-2025-3911
5.2MEDIUM
What is CVE-2025-3911?
A vulnerability in the Docker Desktop application allows for the logging of environment variables configured for running containers. This can result in the unintentional disclosure of sensitive information, such as API keys and passwords, within the application logs. If an unauthorized user gains access to these logs, they could exploit this information to gain further access to other systems or services. To mitigate this risk, Docker has implemented changes starting with version 4.41.0, which prevents the logging of user-defined environment variables.
Affected Version(s)
Docker Desktop Windows 0 < 4.41.0