CVE Vulnerabilities

CVE-2021-45449

Insertion of Sensitive Information into Log File

Published: Jan 12, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the users machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and the user has logged in while on 4.3.0, 4.3.1. Gaining access to this data would require having access to the user’s local files.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
Docker_desktopDocker4.3.0 (including)4.3.0 (including)
Docker_desktopDocker4.3.1 (including)4.3.1 (including)

Potential Mitigations

References