Sensitive Information Exposure in Docker Desktop by Docker
CVE-2025-3911

5.2MEDIUM

Key Information:

Vendor

Docker

Vendor
CVE Published:
29 April 2025

What is CVE-2025-3911?

A vulnerability in the Docker Desktop application allows for the logging of environment variables configured for running containers. This can result in the unintentional disclosure of sensitive information, such as API keys and passwords, within the application logs. If an unauthorized user gains access to these logs, they could exploit this information to gain further access to other systems or services. To mitigate this risk, Docker has implemented changes starting with version 4.41.0, which prevents the logging of user-defined environment variables.

Affected Version(s)

Docker Desktop Windows 0 < 4.41.0

References

CVSS V4

Score:
5.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-3911 : Sensitive Information Exposure in Docker Desktop by Docker