AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-3911

UNKNOWN · CVSS N/A EPSS 0.15%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-04-29 · Last synced 2026-08-04

CyberRota Analysis

This vulnerability has an unknown severity rating. It affects Docker.

CVE
CVE-2025-3911
Severity
UNKNOWN
CVSS
N/A
EPSS
0.15%
Docker

Original NVD Description

Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious actor with read access to these logs could obtain sensitive credentials information and further use it to gain unauthorized access to other systems. Starting with version 4.41.0, Docker Desktop no longer logs environment variables set by the user.