Back

MEDIUM

Exposure of system environment variables in Docker Desktop diagnostic logs

Published Jul 3, 2025

Description

System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc.  A malicious actor with read access to these logs could obtain secrets and further use them to gain unauthorized access to other systems. Starting with version 4.43.0 Docker Desktop no longer logs system environment variables as part of diagnostics log collection.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Docker
Published Jul 3, 2025
Updated Feb 26, 2026
Reserved Jun 24, 2025
CISA Vulnrichment
Updated Jul 4, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Docker
Published Jul 3, 2025
Updated Feb 26, 2026
Exploited since n/a
EUVD-2025-19843