Логотип exploitDog
bind:CVE-2025-0495
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-0495

Количество 9

Количество 9

ubuntu логотип

CVE-2025-0495

3 месяца назад

Buildx is a Docker CLI plugin that extends build capabilities using BuildKit. Cache backends support credentials by setting secrets directly as attribute values in cache-to/cache-from configuration. When supplied as user input, these secure values may be inadvertently captured in OpenTelemetry traces as part of the arguments and flags for the traced CLI command. OpenTelemetry traces are also saved in BuildKit daemon's history records. This vulnerability does not impact secrets passed to the Github cache backend via environment variables or registry authentication.

EPSS: Низкий
nvd логотип

CVE-2025-0495

3 месяца назад

Buildx is a Docker CLI plugin that extends build capabilities using BuildKit. Cache backends support credentials by setting secrets directly as attribute values in cache-to/cache-from configuration. When supplied as user input, these secure values may be inadvertently captured in OpenTelemetry traces as part of the arguments and flags for the traced CLI command. OpenTelemetry traces are also saved in BuildKit daemon's history records. This vulnerability does not impact secrets passed to the Github cache backend via environment variables or registry authentication.

EPSS: Низкий
msrc логотип

CVE-2025-0495

24 дня назад

EPSS: Низкий
debian логотип

CVE-2025-0495

3 месяца назад

Buildx is a Docker CLI plugin that extends build capabilities using Bu ...

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1344-1

2 месяца назад

Security update for docker-stable

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:1341-1

2 месяца назад

Security update for docker

EPSS: Низкий
redos логотип

ROS-20250515-04

около 1 месяца назад

Уязвимость docker-ce

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-m4gq-fm9h-8q75

3 месяца назад

buildx allows a possible credential leakage to telemetry endpoint

EPSS: Низкий
fstec логотип

BDU:2025-06572

3 месяца назад

Уязвимость плагина Docker buildx, связанная с раскрытием информации через регистрационные файлы, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-0495

Buildx is a Docker CLI plugin that extends build capabilities using BuildKit. Cache backends support credentials by setting secrets directly as attribute values in cache-to/cache-from configuration. When supplied as user input, these secure values may be inadvertently captured in OpenTelemetry traces as part of the arguments and flags for the traced CLI command. OpenTelemetry traces are also saved in BuildKit daemon's history records. This vulnerability does not impact secrets passed to the Github cache backend via environment variables or registry authentication.

0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-0495

Buildx is a Docker CLI plugin that extends build capabilities using BuildKit. Cache backends support credentials by setting secrets directly as attribute values in cache-to/cache-from configuration. When supplied as user input, these secure values may be inadvertently captured in OpenTelemetry traces as part of the arguments and flags for the traced CLI command. OpenTelemetry traces are also saved in BuildKit daemon's history records. This vulnerability does not impact secrets passed to the Github cache backend via environment variables or registry authentication.

0%
Низкий
3 месяца назад
msrc логотип
0%
Низкий
24 дня назад
debian логотип
CVE-2025-0495

Buildx is a Docker CLI plugin that extends build capabilities using Bu ...

0%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2025:1344-1

Security update for docker-stable

0%
Низкий
2 месяца назад
suse-cvrf логотип
SUSE-SU-2025:1341-1

Security update for docker

0%
Низкий
2 месяца назад
redos логотип
ROS-20250515-04

Уязвимость docker-ce

CVSS3: 5.9
0%
Низкий
около 1 месяца назад
github логотип
GHSA-m4gq-fm9h-8q75

buildx allows a possible credential leakage to telemetry endpoint

0%
Низкий
3 месяца назад
fstec логотип
BDU:2025-06572

Уязвимость плагина Docker buildx, связанная с раскрытием информации через регистрационные файлы, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 3.3
0%
Низкий
3 месяца назад

Уязвимостей на страницу