CVE Vulnerabilities

CVE-2021-45449

Insertion of Sensitive Information into Log File

Published: Jan 12, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the users machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and the user has logged in while on 4.3.0, 4.3.1. Gaining access to this data would require having access to the user’s local files.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Docker_desktop Docker 4.3.0 (including) 4.3.0 (including)
Docker_desktop Docker 4.3.1 (including) 4.3.1 (including)

Potential Mitigations

References