Home

Description

Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. This poses a risk of leaking sensitive information in exported diagnostics, especially when access denied errors occurred.

PUBLISHED Reserved 2025-11-26 | Published 2025-12-09 | Updated 2025-12-10 | Assigner Docker




LOW: 2.4CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-532 Insertion of Sensitive Information into Log File

Product status

Default status
unaffected

4.51.0 (semver) before 4.54.0
affected

References

docs.docker.com/...op/troubleshoot-and-support/troubleshoot/

cve.org (CVE-2025-13743)

nvd.nist.gov (CVE-2025-13743)

Download JSON