CVE-2025-3911

MEDIUM

Docker Desktop <4.40.9 - Info Disclosure

Title source: llm
STIX 2.1

Description

Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious actor with read access to these logs could obtain sensitive credentials information and further use it to gain unauthorized access to other systems. Starting with version 4.41.0, Docker Desktop no longer logs environment variables set by the user.

Scores

CVSS v4 5.2
EPSS 0.0010
EPSS Percentile 27.8%
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (1)
Docker/Docker Desktop < 4.41.0
Published Apr 29, 2025
Tracked Since Feb 18, 2026