Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qj23-w8jm-w8wv

Опубликовано: 03 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.2

Описание

System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc.  A malicious actor with read access to these logs could obtain secrets and further use them to gain unauthorized access to other systems. Starting with version 4.43.0 Docker Desktop no longer logs system environment variables as part of diagnostics log collection.

System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc.  A malicious actor with read access to these logs could obtain secrets and further use them to gain unauthorized access to other systems. Starting with version 4.43.0 Docker Desktop no longer logs system environment variables as part of diagnostics log collection.

EPSS

Процентиль: 4%
0.00022
Низкий

5.2 Medium

CVSS4

Дефекты

CWE-532

Связанные уязвимости

nvd
около 2 месяцев назад

System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc.  A malicious actor with read access to these logs could obtain secrets and further use them to gain unauthorized access to other systems. Starting with version 4.43.0 Docker Desktop no longer logs system environment variables as part of diagnostics log collection.

EPSS

Процентиль: 4%
0.00022
Низкий

5.2 Medium

CVSS4

Дефекты

CWE-532