Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qj23-w8jm-w8wv

Опубликовано: 03 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.2

Описание

System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc.  A malicious actor with read access to these logs could obtain secrets and further use them to gain unauthorized access to other systems. Starting with version 4.43.0 Docker Desktop no longer logs system environment variables as part of diagnostics log collection.

System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc.  A malicious actor with read access to these logs could obtain secrets and further use them to gain unauthorized access to other systems. Starting with version 4.43.0 Docker Desktop no longer logs system environment variables as part of diagnostics log collection.

EPSS

Процентиль: 7%
0.00026
Низкий

5.2 Medium

CVSS4

Дефекты

CWE-532

Связанные уязвимости

nvd
7 месяцев назад

System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc.  A malicious actor with read access to these logs could obtain secrets and further use them to gain unauthorized access to other systems. Starting with version 4.43.0 Docker Desktop no longer logs system environment variables as part of diagnostics log collection.

CVSS3: 6.5
fstec
7 месяцев назад

Уязвимость диагностических журналов платформы для разработки и доставки контейнерных приложений Docker Desktop, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 7%
0.00026
Низкий

5.2 Medium

CVSS4

Дефекты

CWE-532